PROTOTYPE Dates and CVE are real. Counts come from the full scan of 08–09.09.2026. Values in [brackets] wait for the daily scan.
HackedIndex Check your site
Outbreaks WPMU DEV Dashboard
ACTIVE Tracked since 27.08.2026 · patch out since 24.08.2026

WPMU DEV Dashboard: a single sign-on flaw hands attackers the admin panel

CVECVE-2026-76581
SEVERITYCVSS 9.8Critical
AFFECTEDWPMU DEV Dashboard below 5.0.2WordPress plugin
FIXED IN5.0.2released 24.08.2026
3 daysfrom the patch to the first exploit attempts
5 daysfrom the patch to the first infected site we saw
21infected sites in the index run a WPMU DEV plugin (Smush, Forminator, Hustle)
3of them run a Pro version, which usually installs through the vulnerable Dashboard. The Dashboard itself shows no version in public.
Timeline

Five days from patch to break-in

24.08.2026 Vendor ships the fix, version 5.0.2 Sites that updated before they were attacked are protected from this hole. Everyone else is on the clock.
27.08.2026 First exploit attempts in the wild Three days is how long it took to turn the patch into an attack.
29.08.2026 First infected site observed Casino spam injected through an admin session the owner did not start.
04.09.2026 Hit on a site we monitor A hidden casino block, caught by our content check the same day.
08–09.09.2026 Full scan of Poland 923 confirmed infected sites from all causes. This wave is one of them.
What we see on infected sites

The owner sees a normal site. Google sees a casino.

01
Admin access without a passwordThe flaw lets an attacker sign in through the plugin's single sign-on as an administrator.
02
A hidden block of casino linksWritten into the theme or the database and hidden with CSS, so visitors never see it and search engines always do.
03
Spam pages Google can findSome sites also get casino pages added to the sitemap, or serve a different page only to Googlebot.

Check and fix

Update WPMU DEV Dashboard to 5.0.2 or later, or remove it
Look for administrator accounts you did not create
Search posts, widgets and options for hidden blocks with casino words
Compare your home page as Googlebot and as a visitor
Change every password and the WordPress salts
Resubmit the sitemap and remove the spam URLs in Search Console
Run the free check
Exploited now

Holes that are filling the index

Only vulnerabilities our scan ties to infected sites. Not a copy of every CVE feed.
Software Vulnerability CVSS Fixed in First exploited Index sites Status
WPMU DEV DashboardWordPress plugin
CVE-2026-76581SSO authentication bypass
9.8 5.0.2 27.08.2026 3 Active
A vulnerability joins this table once the scan links it to infected sites. The daily re-check adds the next ones.

Get outbreak alerts

One email per new outbreak, with the version that fixes it. For site owners, agencies and hosts. You confirm by email, and every alert has an unsubscribe link.

Almost done. Confirm in the email we just sent you. No account needed.