ZeroHour
Wordfencepublished ()ingested Alex Thomas

Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin

highVulnerabilityimportance 65
AI summary · glm-5.3-flash

Wordfence researchers disclosed a critical unauthenticated authentication bypass in the WPMU DEV Dashboard plugin, enabling admin takeover and possible RCE.

During internal research on August 19, 2026, Wordfence discovered an authentication bypass in the WPMU DEV Dashboard WordPress plugin, which has roughly 350,000 active installations. Unauthenticated attackers can gain administrator access when Hub Single-Sign On is enabled, enabling complete site takeover. If an administrator-writable code mechanism such as the plugin or theme editor is available, the flaw can lead to remote code execution.

  • Unauthenticated attackers gain admin access when Hub Single-Sign On is enabled.
  • Flaw can escalate to RCE via the WordPress plugin or theme editor.
  • Plugin has an estimated 350,000 active installations.
  • Found August 19, 2026 by Wordfence during internal research.
Full article

On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin with an estimated 350,000 active installations. This vulnerability makes it possible for unauthenticated attackers to gain administrator access when Hub Single-Sign On is enabled. This can lead to complete site takeover and, when an administrator-accessible code-write mechanism such as the WordPress plugin or theme editor is available, remote code execution. The post Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin appeared first on Wordfence.

This source does not provide full text. Read it at wordfence.com.