Authentication Bypass in WPMU DEV Dashboard for WordPress
CVE-2026-15459

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 August 2026

What is CVE-2026-15459?

The WPMU DEV Dashboard plugin for WordPress is susceptible to an authentication bypass flaw. In all versions up to and including 5.0.0, an empty API key allows unauthenticated attackers to forge request signatures, thus compromising site integrity. This vulnerability enables attackers to perform privileged Hub actions such as installing malicious plugins from external URLs, deleting existing plugins and themes, upgrading the WordPress core without authorization, and even logging in as an administrator through Single Sign-On (SSO). Importantly, sites that are connected to a WPMU DEV account with a valid API key are not impacted by this issue.

Affected Version(s)

WPMU DEV Dashboard 0 <= 5.0.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Austin Ginder
.