VYPR

WPMU DEV Dashboard

by WordPress

CVEs (2)

  • CVE-2026-76581CriAug 28, 2026
    risk 0.64cvss 9.8epss 0.00

    The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where…

  • CVE-2026-15459HigAug 6, 2026
    risk 0.53cvss 8.1epss 0.01

    The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature…