Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3814 articles · 205526 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-76581KEVEXPLOITED
wpmudev · WPMU DEV Dashboard

WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion

Description

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 verifies an unseparated concatenation that omits the domain field. This makes it possible for unauthenticated attackers, on sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator, to obtain a valid HMAC from step 1 and replay it to step 2 by moving the domain value into the redirect field, resulting in an authenticated administrator session.

Affected Products

VendorProductVersions
wpmudevWPMU DEV Dashboard0

References

  • https://www.wordfence.com/threat-intel/vulnerabilities/id/3d4321c8-15a4-46f5-9b0e-2098a7fcfb5b?source=cve
  • https://wpmudev.com/project/wpmu-dev-dashboard/

Related News (1 articles)

Tier C
VulDB6h ago
CVE-2026-76581 | WPMU DEV Dashboard Plugin up to 5.0.1 on WordPress SSO wdpsso_step1/wdpsso_step2 domain/redirect improper authentication
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-347
PublishedAug 28, 2026
Last enriched6h ago
Trending Score97
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-18324
Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
Trending: 26
HIGHCVE-2026-18328
Forminator Forms <= 1.57.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter
Trending: 24
CRITICALCVE-2026-15748
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
Trending: 19
HIGHCVE-2026-18323
Forminator Forms <= 1.57.0.2 - Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft)
Trending: 17
MEDIUMCVE-2026-12998
Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 28, 2026
Added to CISA KEV
Aug 28, 2026
Discovered by ZDM
Aug 28, 2026
Actively Exploited
Aug 28, 2026