Skip to main content
QUIETLYTIC
Vulnerability

WPMU DEV Dashboard Authentication Bypass (CVE-2026-76581)

CVE-2026-76581 is a CVSS 9.8 authentication bypass in the WPMU DEV Dashboard plugin allowing administrator session forgery, reported exploited by VulnCheck.

CVE-2026-76581
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
WPMU DEV Dashboard, WPMU DEV Dashboard (through 5.0.1)

CVE-2026-76581 carries a CVSS 3.1 base score of 9.8 against the WPMU DEV Dashboard plugin for WordPress, which connects sites to WPMU DEV’s Hub for centralized management. NVD classifies it as CWE-347 (Improper Verification of a Cryptographic Signature) and states the flaw affects all versions up to and including 5.0.1. VulnCheck’s KEV feed reports the CVE as exploited, dated August 27, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-76581 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description identifies a mismatch between two halves of the same authentication handshake. The plugin’s Single Sign-On flow runs through two unauthenticated AJAX actions, wdpsso_step1 and wdpsso_step2. Step 1 signs and discloses an HMAC (a cryptographic signature) covering an unseparated concatenation of four values: a token, a state, a redirect URL, and a domain. Step 2, which verifies that HMAC before granting a session, checks a concatenation of the same fields but omits the domain field.

Because step 1’s signature covers all four fields concatenated without separators, and step 2 only checks three of them, NVD states an attacker can take a legitimately obtained HMAC from step 1, move the domain value into the redirect field, and replay the result to step 2 — which will verify successfully because it never independently checks the domain. NVD names one precondition: this applies to sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator account, and the result of a successful replay is an authenticated administrator session.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-347 classification, the affected-version ceiling (5.0.1), and the full two-step HMAC-construction mismatch all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Below-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.00339, a 27.2nd percentile score as of our ingestion — on the lower end of our recent KEV coverage despite the confirmed exploitation report and the flaw’s own severity.

No field is in conflict between our two sources. Our data carries no fixed-version field; NVD’s description states only the affected-version ceiling.

Why this matters

This is a case where the EPSS score and the demonstrated real-world impact point in different directions, and we flag that tension rather than let one metric imply the other doesn’t matter: a below-midpoint EPSS percentile reflects a statistical model’s assessment of broad exploitation likelihood, not a judgment about this specific flaw’s severity or about whether the already-reported VulnCheck exploitation is genuine. NVD’s own description makes clear the outcome — full administrator session takeover via signature-verification logic that does not check what it appears to sign — is severe once the stated precondition (Hub SSO enabled, mapped to an administrator) is met.

Because the precondition is specific (Hub SSO plus administrator mapping) rather than universal, actual exposure varies by site configuration in a way a version check alone won’t reveal — similar to the WooCommerce checkout-role CVE elsewhere in our recent coverage, sites should check their own SSO configuration rather than assume a version number settles the question.

Frequently Asked Questions

What is CVE-2026-76581? A CVSS 9.8 authentication bypass vulnerability (CWE-347) in the WPMU DEV Dashboard WordPress plugin, through version 5.0.1, allowing an attacker to replay a manipulated HMAC signature to obtain an authenticated administrator session.

Is CVE-2026-76581 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 27, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

Do I need Hub SSO enabled for my site to be at risk? Yes. NVD states the flaw applies to sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator account.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our data carries no fixed-version field. NVD states versions through 5.0.1 are affected; confirm directly with WPMU DEV whether a later release addresses this specific CVE.


Severity, vector, weakness classification, and the full HMAC-construction mismatch sourced from the National Vulnerability Database record for CVE-2026-76581. Exploitation status and the August 27, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools