Wordfence Finds Critical Admin Takeover Bug in WPMU DEV Dashboard

Wordfence Finds Critical Admin Takeover Bug in WPMU DEV Dashboard

Wordfence reports an authentication bypass in WPMU DEV Dashboard, a plugin with 350,000 installs, letting unauthenticated attackers gain admin access when Hub S…

The WPMU DEV Dashboard WordPress plugin has a critical authentication bypass vulnerability that can let an unauthenticated attacker gain administrator access when a feature called Hub Single Sign-On is enabled, according to a security research report published by Wordfence Argus on August 19th, 2026. Wordfence Argus is the threat research team at Wordfence, a company that builds WordPress security tools and services. The plugin is used on an estimated 350,000 active installations.

An authentication bypass is a weakness that allows someone to skip the normal login step and get into an account or area as if they were a valid user. In this case, the vulnerability only applies when Hub Single Sign-On, often shortened to Hub SSO, is turned on. Hub SSO is a setting that lets a person log in to a WordPress website through the WPMU DEV Hub service instead of typing a separate WordPress password. When Hub SSO is active, the flaw makes it possible for an unauthenticated attacker, meaning someone who is not logged in and has no account on the site, to obtain administrator access.

Administrator access is the highest permission level in WordPress and gives full control over the website. An attacker with this access can change passwords, add new administrator accounts, install malicious plugins, modify pages, and read any data stored in WordPress. The Wordfence report notes that when an administrator-accessible code-write mechanism such as the WordPress plugin editor or theme editor is available, the situation can escalate to remote code execution. Remote code execution means the attacker can run their own commands or programs on the server that hosts the website, which can put the entire hosting account at risk.

The vulnerability was found during internal research by Wordfence Argus. The published report does not include detailed technical information about the exact flaw, and it does not say whether a patch was available at the time of publication. Because the issue is triggered only when Hub Single Sign-On is enabled, sites that have not activated that feature are not exposed through this specific vulnerability. Site owners who use the plugin should check their settings immediately.

For website owners, the immediate step is to review the Hub Single Sign-On setting in the WPMU DEV Dashboard. If Hub SSO is not needed, it should be turned off. If it is needed, site owners should watch for an update from WPMU DEV and apply it as soon as it is released. Limiting access to the WordPress plugin and theme editor can also reduce the risk of remote code execution even if an attacker somehow gains administrator access.

WordPress plugin vulnerabilities can provide a direct path into a website, especially when a plugin is as widely installed as WPMU DEV Dashboard. Because plugins extend the base WordPress software with new functions, a weakness in any one of them can undermine the security of the whole site. This is why plugin updates and configuration reviews are an important part of routine website maintenance. Managed WordPress hosting services such as AEU Hosting provide a secured, end-to-end environment that can help website owners keep their installations and plugins better maintained.

How to Protect Yourself

  1. Turn off Hub Single Sign-On in your WPMU DEV Dashboard settings right away if you do not actively use it.
  2. Check the WPMU DEV Dashboard plugin page for an update, and install any security fix as soon as it becomes available.
  3. If you cannot update yet, temporarily deactivate the WPMU DEV Dashboard plugin to remove the risk.
  4. In your WordPress admin area, disable the plugin and theme editor so an attacker cannot use it to run malicious code even if they get admin access.
  5. Make a full backup of your website now, so you can restore it quickly if anything goes wrong.

Terms Explained

  • Authentication Bypass A security weakness that lets someone skip the normal login step and get into an account or area as if they were a valid user.
  • Hub Single Sign-On (SSO) A setting that lets a person log in to a WordPress website through the WPMU DEV Hub service instead of using a separate WordPress password.
  • Remote Code Execution A serious type of attack where an outsider can run their own commands or programs on the computer that hosts a website.
  • Plugin Editor A built-in WordPress tool that lets an administrator edit plugin files directly from the website dashboard.
  • Unauthenticated Attacker Someone who is not logged in and has no account on the website, but still tries to break in.
  • Administrator Access The highest permission level in WordPress, which allows a user to change settings, install software, and manage everything on the site.

Related AEU services