What You Need to Know
A critical security vulnerability has been discovered in the WPMU DEV Dashboard plugin, a widely used tool with an estimated 350,000 active installations that connects WordPress sites to WPMU DEV services. The vulnerability allows unauthenticated attackers to gain administrator access to affected sites when Hub Single Sign-On (SSO) is enabled, potentially leading to complete site takeover and remote code execution.
At BG Cyber Connect, we take proactive security seriously. Here is what you need to know about this vulnerability and the steps you must take to protect your website.
Understanding the Vulnerability
The vulnerability was discovered by Wordfence’s internal research team, Wordfence Argus, on August 19, 2026, during routine security research. It affects all versions of WPMU DEV Dashboard up to and including version 5.0.1.
How the Attack Works
WPMU DEV Dashboard implements a Hub SSO flow through two AJAX actions: wdpsso_step1 and wdpsso_step2. Both actions are accessible by unauthenticated visitors, which is necessary for the SSO flow since the visitor is not yet authenticated when the exchange begins.
The vulnerability arises from a critical flaw in how these two steps handle cryptographic signatures:
- Step 1 creates an HMAC-SHA256 signature by concatenating the token, hashed state, redirect value, and site domain—without any delimiters or length prefixes.
- Step 2 independently constructs the message it expects the Hub to have signed. However, it concatenates only the token, state, and redirect values, omitting the domain field entirely.
This creates an ambiguity between the two signed messages. Because the fields are concatenated without unambiguous boundaries, an unauthenticated attacker can exploit this inconsistency.
The Exploit in Practice
An attacker can request step 1 with an empty redirect value. Step 1 then signs token || state || domain. The attacker can replay that same HMAC to step 2 while placing the returned domain in the step-2 redirect field. Since step 2 also constructs token || state || domain, the two byte strings are identical even though the domain occupies a different logical field.
The attacker does not need to know the WPMU DEV API key. Step 1 effectively acts as a signing oracle, returning a valid HMAC that step 2 accepts for a different interpretation of the same concatenated bytes.
The Consequence
Once the checks pass, the plugin creates an authentication cookie for the WordPress user configured for Hub SSO. On sites where SSO is mapped to an administrator, the unauthenticated attacker receives an administrator session—granting complete control of the WordPress site.
Who Is at Risk?
Your site is vulnerable if:
- You are running WPMU DEV Dashboard version 5.0.1 or earlier
- Your site is connected to WPMU DEV services
- Hub SSO is enabled on your site
Important note: This vulnerability is distinct from an earlier WPMU DEV Dashboard authentication bypass that affected versions up to and including 5.0.0. That earlier issue involved empty-key WDP-AUTH validation and affected unconnected sites through the Hub remote-request path. This new vulnerability affects connected sites with Hub SSO enabled and remains exploitable in version 5.0.1 despite the protections added for the earlier issue.
The Good News: A Patch Is Available
The WPMU DEV team responded promptly to the disclosure. After receiving full disclosure details on August 19, 2026, the developer acknowledged the report and submitted a pre-release patch for review on August 21. The patch was released to the public as version 5.0.2 on August 24, 2026.
How the Patch Works
The vendor’s patch stores the HMAC created during step 1 in a server-side SSO setting. Step 2 then validates that this stored value has the expected format and rejects the request when the incoming signature is the same signature produced by step 1. A successful legitimate SSO exchange clears the temporary value.
Wordfence tested the reported attack against the patched build and confirmed that replaying the step-1 HMAC in step 2 was rejected without creating a login cookie, while legitimate SSO flows continued to work correctly.
What You Must Do Now
1. Update Immediately
The single most critical action is to update WPMU DEV Dashboard to version 5.0.2 or later.
To update:
- Log in to your WordPress dashboard
- Navigate to Plugins → Installed Plugins
- Find “WPMU DEV Dashboard” and click “Update Now”
2. If You Cannot Update Immediately
Sites that cannot update immediately should disable Hub SSO until the patched version has been installed.
3. Enable a Web Application Firewall
Wordfence Premium, Care, and Response customers received a firewall rule protecting against known exploitation techniques on August 25, 2026. Sites using the free version of Wordfence will receive the same protection 30 days later, on September 24, 2026.
If you use Wordfence, ensure your firewall is active and your rules are up to date. If you use a different security solution, verify that it provides equivalent protection.
4. Review Your Site for Indicators of Compromise
If your site was running a vulnerable version with Hub SSO enabled, we strongly recommend reviewing your site for signs of unauthorised access, including:
- Unexpected administrator accounts
- Unfamiliar plugins or themes
- Modified core files or unexpected code in your WordPress installation
How BG Cyber Connect Can Help
At BG Cyber Connect, we understand that keeping your WordPress site secure requires constant vigilance. Our team can:
- Perform an immediate security audit to verify your WPMU DEV Dashboard version and identify any other vulnerabilities
- Review your site for indicators of compromise and remediate any infections
- Implement proactive security monitoring, including Web Application Firewall (WAF) protection
- Provide ongoing patch management to ensure critical updates are applied promptly
We have previously covered several critical WordPress vulnerabilities, including the UpdraftPlus authentication bypass, the All-in-One WP Migration SQL injection, and the Elementor Pro unauthenticated file upload.
Additional Resources
For a complete technical analysis of this vulnerability, read Wordfence’s detailed breakdown:
- Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin
- WPMU DEV Dashboard Plugin Page
- Wordfence Vulnerability Management Portal
The Bottom Line
Update WPMU DEV Dashboard to version 5.0.2 now. This vulnerability allows unauthenticated attackers to gain administrator access on sites with Hub SSO enabled. The patch is available, and the risk of exploitation is significant.
Need Help Securing Your WordPress Site?
Contact BG Cyber Connect for an Immediate Security Assessment
Explore our comprehensive WordPress security services:
BGCC Cybersecurity Solutions


