CVE-2026-76581: WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion

Published Aug 28, 2026
·
Updated

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated wdpssostep1 and wdpssostep2 AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 verifies an unseparated concatenation that omits the domain field. This makes it possible for unauthenticated attackers, on sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator, to obtain a valid HMAC from step 1 and replay it to step 2 by moving the domain value into the redirect field, resulting in an authenticated administrator session.

Affected Software

1 affected component
WPMU DEV WPMU DEV Dashboard plugin for WordPress<=5.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WordPress plugin: WPMU DEV Dashboard to a version that resolves this vulnerability.

    Fixed in 5.0.1Patch WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion

Event History

Aug 28, 2026
CVE Published
via MITRE·06:39 AM
Data Sourced
via MITRE·06:39 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to exploitation?

Sites running WPMU DEV Dashboard version 5.0.1 or earlier are exposed when they are connected to WPMU DEV, have Hub SSO enabled, and have that SSO mapped to an administrator account.

2

What access does an attacker need?

No authentication, privileges, or user interaction are required. An attacker can use the unauthenticated SSO AJAX actions to obtain an HMAC and replay it with manipulated fields.

3

What is the resulting impact if exploitation succeeds?

Successful exploitation results in an authenticated WordPress administrator session. This gives the attacker administrator-level access to the affected site.

4

Is a default installation necessarily affected?

No. Exploitation depends on Hub SSO being enabled and mapped to an administrator, in addition to the site using an affected plugin version and being connected to WPMU DEV.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203