Authentication Bypass in WPMU DEV Dashboard for WordPress
CVE-2026-15459
8.1HIGH
What is CVE-2026-15459?
The WPMU DEV Dashboard plugin for WordPress is susceptible to an authentication bypass flaw. In all versions up to and including 5.0.0, an empty API key allows unauthenticated attackers to forge request signatures, thus compromising site integrity. This vulnerability enables attackers to perform privileged Hub actions such as installing malicious plugins from external URLs, deleting existing plugins and themes, upgrading the WordPress core without authorization, and even logging in as an administrator through Single Sign-On (SSO). Importantly, sites that are connected to a WPMU DEV account with a valid API key are not impacted by this issue.
Affected Version(s)
WPMU DEV Dashboard 0 <= 5.0.0