wpmudev Vulnerabilities and Affected Products
Vulnerabilities associated with WPMU DEV Dashboard.
Products
Clear product- Forminator Forms – Contact Form, Payment Form & Custom Form Builder25 vulnerabilities
- Branda – White Label & Branding, Free Login Page Customizer5 vulnerabilities
- Hustle – Email Marketing, Lead Generation, Optins, Popups5 vulnerabilities
- defender_security4 vulnerabilities
- Broken Link Checker3 vulnerabilities
- SmartCrawl SEO checker, analyzer & optimizer3 vulnerabilities
- hustle2 vulnerabilities
- smartcrawl2 vulnerabilities
- Appointments1 vulnerability
- branda1 vulnerability
- branda_white_label_wordpress_custom_login_page_customizer1 vulnerability
- broken_link_checker1 vulnerability
- Defender Security – Malware Scanner, Login Security & Firewall1 vulnerability
- forminator_forms1 vulnerability
- Hummingbird Performance - Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN1 vulnerability
- Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN1 vulnerability
- Smush – Image Optimization, Compression, Lazy Load, WebP & CDN1 vulnerability
- WPMU DEV Dashboard1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-15459HIGH | WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= EndpointThe WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signature verified by validate_hash() trivially forgeable; version 5.0.0 additionally removed the replay check in validate_nonce(), and the remote handler is bound to the public init hook with no capabilit… CWE-287Aug 6, 2026 | CVSS8.1v3.1 | EPSS0.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |