{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-76581/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-76581"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPMU DEV Dashboard"],"_cs_severities":["critical"],"_cs_tags":["wordpress","authentication-bypass","cve-2026-76581"],"_cs_type":"advisory","_cs_vendors":["WPMU DEV"],"content_html":"\u003cp\u003eThe WPMU DEV Dashboard plugin for WordPress (versions 5.0.1 and earlier) contains a critical authentication bypass vulnerability identified as CVE-2026-76581. The flaw stems from inconsistent HMAC message construction during the Hub SSO authentication process, specifically between the \u003ccode\u003ewdpsso_step1\u003c/code\u003e and \u003ccode\u003ewdpsso_step2\u003c/code\u003e AJAX actions. The plugin fails to consistently separate concatenated values within the token generation logic.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can capture the signed output from the first step - which includes the token, state, redirect, and domain parameters - and manipulate the input to the second step. By moving the domain value into the redirect field, the attacker creates a payload that satisfies the validation logic in the second AJAX action, which unexpectedly omits the domain field from its verification check. Successful exploitation grants the attacker an authenticated administrator session, posing a significant risk for complete site takeover. Organizations using the WPMU DEV Dashboard with Hub SSO enabled are at risk and should prioritize immediate remediation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-76581 allows unauthenticated actors to gain full administrative control over the affected WordPress installation. This provides unrestricted access to site configurations, data, and themes, effectively bypassing all authentication controls. Given the widespread use of WPMU DEV plugins, the number of potentially affected WordPress environments is high, particularly among managed hosting services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WPMU DEV Dashboard plugin to version 5.0.2 or later immediately to resolve the flawed HMAC construction logic.\u003c/li\u003e\n\u003cli\u003eDisable the \u0026quot;Hub SSO\u0026quot; feature if it is not currently required for administrative access while the patch process is underway.\u003c/li\u003e\n\u003cli\u003eAudit access logs for repetitive or unusual POST requests targeting \u003ccode\u003eadmin-ajax.php\u003c/code\u003e involving the \u003ccode\u003ewdpsso_step1\u003c/code\u003e and \u003ccode\u003ewdpsso_step2\u003c/code\u003e actions, particularly those demonstrating atypical parameter concatenation or unexpected redirects.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T09:13:07Z","date_published":"2026-08-28T09:13:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wpmu-dev-auth-bypass/","summary":"An authentication bypass vulnerability in the WPMU DEV Dashboard WordPress plugin allows unauthenticated attackers to forge an administrator session by exploiting flawed HMAC validation in the Hub SSO flow.","title":"Authentication Bypass in WPMU DEV Dashboard Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wpmu-dev-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-76581","version":"https://jsonfeed.org/version/1.1"}