What is CVE-2026-15459?
The WPMU DEV Dashboard plugin for WordPress contains an authentication bypass vulnerability on sites not connected to the WPMU DEV Hub. In its default state, the site API key used for the WDP-AUTH request signature is empty, allowing an attacker to forge the signature and gain unauthorized access. Users should update the plugin or connect to the Hub immediately.
Azərbaycanca: WordPress üçün WPMU DEV Dashboard plaginində autentifikasiyadan yan keçmə zəifliyi aşkarlanıb. Plugin WPMU DEV Hub-a qoşulmayan saytlarda defolt olaraq boş API açarından istifadə etdiyinə görə, təcavüzkar WDP-AUTH imzasını manipulyasiya edərək sistemə daxil ola bilir. İstifadəçilərə dərhal plaqini yeniləmək və ya Hub-a qoşulmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
In what situation does the authentication bypass vulnerability occur in the WPMU DEV Dashboard plugin?
This vulnerability occurs when the site is not connected to the WPMU DEV Hub and the plugin uses an empty API key by default.
How can an attacker exploit the empty API key to gain unauthorized access?
An attacker can forge the WDP-AUTH request signature to gain unauthorized access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.