THREATOPS
THREAT OPSThreat News › Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin

Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin

medwordfencePublished 2026-08-27

<p>On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in <a href="https://wpmudev.com/project/wpmu-dev-dashboard/" rel="noopener" target="_blank">WPMU DEV Dashboard</a>, a WordPress plugin with an estimated 350,000 active installations. This vulnerability makes it possible for unauthenticated attackers to gain administrator access when Hub Single-Si

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-critical-authentication-bypass-in-wpmu-dev-dashboard-plugin/