CVE-2026-16051: WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote code execution).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wpmudev-updates WordPress pluginto a version that resolves this vulnerability.Fixed in 5.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16051?
CVE-2026-16051 has a risk score of 79, indicating a high severity threat.
How do I fix CVE-2026-16051?
To mitigate CVE-2026-16051, update the WPMU DEV Dashboard plugin to version 5.0.1 or later.
What type of vulnerability is CVE-2026-16051?
CVE-2026-16051 is classified as a Remote Code Execution vulnerability due to code injection flaws.
How does CVE-2026-16051 impact my WordPress site?
CVE-2026-16051 can allow attackers to execute arbitrary code on your WordPress site if exploited.
What plugin is affected by CVE-2026-16051?
CVE-2026-16051 affects the WPMU DEV Dashboard plugin for WordPress versions prior to 5.0.1.