Critical Authentication Bypass Discovered in WPMU DEV Dashboard Plugin

A critical security vulnerability has been discovered in the WPMU DEV Dashboard plugin, used on an estimated 350,000 WordPress sites. The flaw allows unauthenticated attackers to gain administrator access when Hub SSO is enabled, potentially leading to complete site takeover. A patch (version 5.0.2) is available. Update immediately or disable Hub SSO.

What You Need to Know

A critical security vulnerability has been discovered in the WPMU DEV Dashboard plugin, a widely used tool with an estimated 350,000 active installations that connects WordPress sites to WPMU DEV services. The vulnerability allows unauthenticated attackers to gain administrator access to affected sites when Hub Single Sign-On (SSO) is enabled, potentially leading to complete site takeover and remote code execution.

At BG Cyber Connect, we take proactive security seriously. Here is what you need to know about this vulnerability and the steps you must take to protect your website.

Understanding the Vulnerability

The vulnerability was discovered by Wordfence’s internal research team, Wordfence Argus, on August 19, 2026, during routine security research. It affects all versions of WPMU DEV Dashboard up to and including version 5.0.1.

How the Attack Works

WPMU DEV Dashboard implements a Hub SSO flow through two AJAX actions: wdpsso_step1 and wdpsso_step2. Both actions are accessible by unauthenticated visitors, which is necessary for the SSO flow since the visitor is not yet authenticated when the exchange begins.

The vulnerability arises from a critical flaw in how these two steps handle cryptographic signatures:

  • Step 1 creates an HMAC-SHA256 signature by concatenating the token, hashed state, redirect value, and site domain—without any delimiters or length prefixes.
  • Step 2 independently constructs the message it expects the Hub to have signed. However, it concatenates only the token, state, and redirect values, omitting the domain field entirely.

This creates an ambiguity between the two signed messages. Because the fields are concatenated without unambiguous boundaries, an unauthenticated attacker can exploit this inconsistency.

The Exploit in Practice

An attacker can request step 1 with an empty redirect value. Step 1 then signs token || state || domain. The attacker can replay that same HMAC to step 2 while placing the returned domain in the step-2 redirect field. Since step 2 also constructs token || state || domain, the two byte strings are identical even though the domain occupies a different logical field.

The attacker does not need to know the WPMU DEV API key. Step 1 effectively acts as a signing oracle, returning a valid HMAC that step 2 accepts for a different interpretation of the same concatenated bytes.

The Consequence

Once the checks pass, the plugin creates an authentication cookie for the WordPress user configured for Hub SSO. On sites where SSO is mapped to an administrator, the unauthenticated attacker receives an administrator session—granting complete control of the WordPress site.

Who Is at Risk?

Your site is vulnerable if:

  • You are running WPMU DEV Dashboard version 5.0.1 or earlier
  • Your site is connected to WPMU DEV services
  • Hub SSO is enabled on your site

Important note: This vulnerability is distinct from an earlier WPMU DEV Dashboard authentication bypass that affected versions up to and including 5.0.0. That earlier issue involved empty-key WDP-AUTH validation and affected unconnected sites through the Hub remote-request path. This new vulnerability affects connected sites with Hub SSO enabled and remains exploitable in version 5.0.1 despite the protections added for the earlier issue.

The Good News: A Patch Is Available

The WPMU DEV team responded promptly to the disclosure. After receiving full disclosure details on August 19, 2026, the developer acknowledged the report and submitted a pre-release patch for review on August 21. The patch was released to the public as version 5.0.2 on August 24, 2026.

How the Patch Works

The vendor’s patch stores the HMAC created during step 1 in a server-side SSO setting. Step 2 then validates that this stored value has the expected format and rejects the request when the incoming signature is the same signature produced by step 1. A successful legitimate SSO exchange clears the temporary value.

Wordfence tested the reported attack against the patched build and confirmed that replaying the step-1 HMAC in step 2 was rejected without creating a login cookie, while legitimate SSO flows continued to work correctly.

What You Must Do Now

1. Update Immediately

The single most critical action is to update WPMU DEV Dashboard to version 5.0.2 or later.

To update:

  • Log in to your WordPress dashboard
  • Navigate to Plugins → Installed Plugins
  • Find “WPMU DEV Dashboard” and click “Update Now”

2. If You Cannot Update Immediately

Sites that cannot update immediately should disable Hub SSO until the patched version has been installed.

3. Enable a Web Application Firewall

Wordfence Premium, Care, and Response customers received a firewall rule protecting against known exploitation techniques on August 25, 2026. Sites using the free version of Wordfence will receive the same protection 30 days later, on September 24, 2026.

If you use Wordfence, ensure your firewall is active and your rules are up to date. If you use a different security solution, verify that it provides equivalent protection.

4. Review Your Site for Indicators of Compromise

If your site was running a vulnerable version with Hub SSO enabled, we strongly recommend reviewing your site for signs of unauthorised access, including:

  • Unexpected administrator accounts
  • Unfamiliar plugins or themes
  • Modified core files or unexpected code in your WordPress installation

How BG Cyber Connect Can Help

At BG Cyber Connect, we understand that keeping your WordPress site secure requires constant vigilance. Our team can:

  • Perform an immediate security audit to verify your WPMU DEV Dashboard version and identify any other vulnerabilities
  • Review your site for indicators of compromise and remediate any infections
  • Implement proactive security monitoring, including Web Application Firewall (WAF) protection
  • Provide ongoing patch management to ensure critical updates are applied promptly

We have previously covered several critical WordPress vulnerabilities, including the UpdraftPlus authentication bypass, the All-in-One WP Migration SQL injection, and the Elementor Pro unauthenticated file upload.

Additional Resources

For a complete technical analysis of this vulnerability, read Wordfence’s detailed breakdown:

The Bottom Line

Update WPMU DEV Dashboard to version 5.0.2 now. This vulnerability allows unauthenticated attackers to gain administrator access on sites with Hub SSO enabled. The patch is available, and the risk of exploitation is significant.

Need Help Securing Your WordPress Site?

Contact BG Cyber Connect for an Immediate Security Assessment

Explore our comprehensive WordPress security services:
BGCC Cybersecurity Solutions

Schedule Appointment

Book Now!