30 August 2026
Reference: CVE-2026-76581
1. What is being reported?
The WPMU DEV Dashboard plugin has a flaw in how it checks login requests when using its Hub Single Sign-On feature. Attackers can trick the system by reusing a valid security token in a way that bypasses normal login checks, giving them full administrator access without needing a password.
2. What this means in plain English
If your website uses this plugin with Hub SSO enabled and your administrator account is linked, someone could take over your site without your permission. This could lead to data loss, website defacement, or other harmful actions.
3. Could this affect a small business?
Small organisations using WordPress with the WPMU DEV Dashboard plugin up to version 5.0.1 and Hub SSO enabled could be at risk. If you do not use this plugin or do not have Hub SSO set up, you are probably not affected.
4. What to do now
- Check if your WordPress site uses the WPMU DEV Dashboard plugin and confirm the version.
- If you use this plugin with Hub SSO enabled, update it immediately to a version newer than 5.0.1 once available.
- If an update is not yet available, consider disabling the plugin or Hub SSO feature until the fix is applied.
- Ask your IT provider to review your website’s administrator accounts and monitor for any unusual activity.
5. Ask your IT provider
Can you confirm if our WordPress site uses the WPMU DEV Dashboard plugin with Hub SSO enabled, and if so, has it been updated to fix the CVE-2026-76581 vulnerability?
6. Bottom line
If you use this plugin with Hub SSO, act quickly to update or disable it to prevent hackers from taking over your website.
Information based on CISA KEV, NVD, and reputable security news reporting.