CVE-2026-16051
Deferred Deferred - Pending Action

Remote Code Execution in WPMU DEV Updates Plugin

Vulnerability report for CVE-2026-16051, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-26

Assigner: WPScan

Description

The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote code execution).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-26
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpmudev wpmudev_updates to 5.0.1 (exc)
wpmudev wpmudev_dashboard to 5.0.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the wpmudev-updates WordPress plugin before version 5.0.1. It allows an attacker to execute arbitrary code on a system by exploiting unsigned or replayed management requests. The plugin fails to verify package integrity and lacks replay protection, enabling malicious code installation.

Detection Guidance

Check if the WPMU DEV Dashboard plugin version is below 5.0.1. Use WordPress admin panel or run a command like 'wp plugin list' if using WP-CLI to verify versions.

Impact Analysis

An attacker could gain full control of your WordPress site or server by exploiting this flaw. This could lead to data theft, malware distribution, or complete system compromise. The impact includes unauthorized access, potential data breaches, and disruption of services.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized access to personal or health data. Organizations may face legal penalties, fines, or reputational damage due to data breaches caused by this flaw.

Mitigation Strategies

Update the WPMU DEV Dashboard plugin to version 5.0.1 or later immediately. Remove or disable the plugin if an update is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16051. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart