Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin 

SecurityVendor

On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin with an estimated 350,000 active installations. This vulnerability makes it possible for unauthenticated attackers to gain administrator access when Hub Single-Sign On is enabled. This can lead to complete site takeover and, when an administrator-accessible code-write mechanism such as the WordPress plugin or theme editor is available, remote code execution.
The post Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin appeared first on Wordfence.WordfenceRead More