On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin with an estimated 350,000 active installations. This vulnerability makes it possible for unauthenticated attackers to gain administrator access when Hub Single-Sign On is enabled. This can lead to complete site takeover and, when an administrator-accessible code-write mechanism such as the WordPress plugin or theme editor is available, remote code execution.
I discovered this vulnerability with the help of Wordfence Argus, which we covered in a separate post. Our mission is to secure WordPress through defense in depth, which is why
Click here to continue reading this article.
