Web_Logo
Remote Support
Security Alert: Critical Flaw in Popular WordPress Plugin
Home » Security Alerts  »  Security Alert: Critical Flaw in Popular WordPress Plugin

Security Alert: Critical Flaw in Popular WordPress Plugin

A critical security flaw in a widely used WordPress plugin let attackers log in as an administrator without a password. If your website runs WordPress, this is worth checking today.

  • What it is: The WPMU DEV Dashboard plugin, installed on roughly 350,000 sites, had a bug that let an attacker forge a valid login session and gain full administrator access.
  • Who is affected: WordPress sites running the WPMU DEV Dashboard plugin, version 5.0.1 or earlier, with Hub SSO enabled.
  • What the risk is: An attacker with admin access can install malicious code, steal customer data, or take the site offline entirely. This is the second bug of its kind in this plugin within a month.
  • What to do: Update the plugin to version 5.0.2 or later without delay. Businesses unsure whether their site uses this plugin should ask their web developer or IT provider to check.

We recommend businesses treat plugin updates as a standing priority, not an occasional chore. A five-minute update is far cheaper than a compromised website.