plugin

Wpmudev Updates Vulnerabilities

2 known security issues reported for the Wpmudev Updates WordPress plugin. Most recent disclosed Aug 27, 2026.

1 critical 1 high

Running Wpmudev Updates on your site? Check whether your installed version is affected.

Scan your site free

WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion

critical

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated...

CVSS:
9.8
Affected:
up to 5.0.1
Fixed in:
5.0.2
Disclosed:
Aug 27, 2026

CVE-2026-76581 on NVD →

WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint

high

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signature verified by val...

CVSS:
8.1
Affected:
up to 5.0.0
Fixed in:
5.0.1
Disclosed:
Aug 5, 2026

CVE-2026-15459 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database