WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action
Summary
| CVE | CVE-2026-16051 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-12 06:18:15 UTC |
| Updated | 2026-08-12 06:18:15 UTC |
| Description | The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote code execution). |
Risk And Classification
Problem Types: CWE-94 Improper Control of Generation of Code ('Code Injection')
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Wpmudev-updates | affected 5.0.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/8dae5fbf-2e9d-4978-b97d-a20e076cd309 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Mike Gozdiskowski (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.