Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-08-30 ยท updated: 2026-08-30 ยท tags: [cve, wordpress, wpmu-dev-dashboard, auth-bypass, account-takeover, critical] ยท confidence: high ยท severity: critical ยท affected_sectors: [Global (Macro)] ยท au_impact: false

CVE-2026-76581

CVE-2026-76581 is a critical authentication-bypass vulnerability (CVSS 9.8) in the WPMU DEV Dashboard WordPress plugin. The flaw allows an unauthenticated attacker to bypass authentication through the Hub single sign-on flow and take over an administrator account, giving full control of the affected site.

Disclosed by Wordfence and Patchstack on 29 August 2026 as part of five critical WordPress plugin and theme flaws, the WPMU DEV Dashboard ships with the widely used WPMU DEV product suite. No in-the-wild exploitation had been disclosed at publication, but the authentication-bypass nature of the flaw warrants urgent patching before attackers weaponise it.

Source