CVE-2026-76581 is an unauthenticated authentication-bypass vulnerability in WPMU DEV Dashboard for WordPress versions through 5.0.1. The unauthenticated Hub SSO AJAX workflow constructs the HMAC input inconsistently between its first and second steps. The first step signs an undelimited concatenation including token, state, redirect, and domain values, while the second verifies a concatenation that omits the domain value. An attacker can obtain a valid HMAC from the first step and replay it to the second step by placing the domain value in the redirect field. This causes the plugin to establish an authenticated WordPress session for the account configured for Hub SSO.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication-bypass vulnerability in WPMU DEV Dashboard for WordPress through version 5.0.1. Ambiguous, inconsistent HMAC message construction in the wdpsso_step1 and wdpsso_step2 unauthenticated AJAX actions enables an attacker to reuse a valid HMAC with manipulated field placement and obtain an administrator session where Hub SSO is enabled and mapped to an administrator.
Critical (CVSS 9.8) network-reachable authentication-bypass vulnerability in the WPMU DEV Dashboard WordPress plugin through version 5.0.1. Ambiguous, inconsistent HMAC canonicalization in Hub SSO AJAX flows permits a valid signature obtained in step 1 to be replayed to step 2 with manipulated parameter boundaries, yielding an administrator session on sites with Hub SSO enabled and mapped to an administrator.
Critical (CVSS 9.8) unauthenticated authentication-bypass flaw caused by ambiguous, inconsistent HMAC message construction between the wdpsso_step1 and wdpsso_step2 Hub SSO AJAX actions. On connected sites with Hub SSO enabled and mapped to an administrator, exploitation can yield full administrator access and site compromise.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.