A critical vulnerability in WPMU DEV Dashboard, a plugin installed on an estimated 350,000 WordPress sites, lets an attacker log in as your administrator without ever entering a password.

What happened

Wordfence says the flaw is an authentication bypass that lets an unauthenticated attacker gain administrator access when Hub Single Sign-On is enabled on your site. Hub SSO lets you log into your WordPress dashboard directly from WPMU DEV’s central Hub account instead of typing your WordPress password. That convenience feature is what the flaw abuses.

Once an attacker has admin access, they control the entire site. Wordfence says the risk goes further if the WordPress plugin or theme editor is available to admins, since that editor gives an attacker a direct path to running their own code on the server.

Wordfence discovered the bug on August 19, 2026, with help from Wordfence Argus, an internal AI system the company built for vulnerability research. Wordfence reported it to WPMU DEV the same day through its Vulnerability Management Portal. WPMU DEV acknowledged the report and submitted a pre-release patch for review two days later, and shipped the fix publicly as version 5.0.2 on August 24, 2026.

What to do

  1. Update WPMU DEV Dashboard to version 5.0.2 or later from your WordPress dashboard.
  2. Check whether Hub Single Sign-On is enabled on your site. If it is, treat the update as urgent rather than routine.
  3. Review your admin user list and recent login activity for anything you don’t recognize since August 19, 2026, when the vulnerability was discovered.
  4. If your site gives admins access to the plugin or theme editor, consider disabling it under Users > Profile or via a security plugin, which removes one path attackers could use to escalate a compromise into full code execution.

WPMU DEV responded quickly here, patching within five days of discovery. That doesn’t remove the risk for sites that haven’t updated yet, so don’t wait to apply it.


End of article