Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw in Popular WordPress Plugin Could Let Hackers Take Over Your Website

A serious security weakness has been found in the WPMU DEV Dashboard plugin for WordPress that could allow attackers to gain administrator access without logging in. This matters because it could let hackers control your website, potentially stealing data or causing damage.

30 August 2026

Reference: CVE-2026-76581

1. What is being reported?

The WPMU DEV Dashboard plugin has a flaw in how it checks login requests when using its Hub Single Sign-On feature. Attackers can trick the system by reusing a valid security token in a way that bypasses normal login checks, giving them full administrator access without needing a password.

2. What this means in plain English

If your website uses this plugin with Hub SSO enabled and your administrator account is linked, someone could take over your site without your permission. This could lead to data loss, website defacement, or other harmful actions.

3. Could this affect a small business?

Small organisations using WordPress with the WPMU DEV Dashboard plugin up to version 5.0.1 and Hub SSO enabled could be at risk. If you do not use this plugin or do not have Hub SSO set up, you are probably not affected.

4. What to do now

  • Check if your WordPress site uses the WPMU DEV Dashboard plugin and confirm the version.
  • If you use this plugin with Hub SSO enabled, update it immediately to a version newer than 5.0.1 once available.
  • If an update is not yet available, consider disabling the plugin or Hub SSO feature until the fix is applied.
  • Ask your IT provider to review your website’s administrator accounts and monitor for any unusual activity.

5. Ask your IT provider

Can you confirm if our WordPress site uses the WPMU DEV Dashboard plugin with Hub SSO enabled, and if so, has it been updated to fix the CVE-2026-76581 vulnerability?

6. Bottom line

If you use this plugin with Hub SSO, act quickly to update or disable it to prevent hackers from taking over your website.

Information based on CISA KEV, NVD, and reputable security news reporting.

Back to Vulnerability Briefs