Summary
WPMU DEV patched two critical vulnerabilities in its Dashboard plugin, including an actively exploited CVSS 9.8 authentication bypass that allows unauthenticated attackers to gain full administrator access via SSO HMAC manipulation.
Take Action:
If you use the WPMU DEV Dashboard plugin on your WordPress site, update it to version 5.0.2 or later right away. Attackers are already using these flaws to take over sites as administrators. If you can't update immediately, turn off the Hub SSO feature, and check your logs for suspicious requests to wdpsso_step1 and wdpsso_step2 in case someone already breached your site.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)