Threats Tagged 'cve-2026-15459'
View all threats tagged with 'cve-2026-15459'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-15459'
Click on any threat for detailed analysis and mitigation recommendations
The WPMU DEV Dashboard plugin for WordPress contains an authentication bypass vulnerability in all versions up to and including 5.0.0. This flaw allows unauthenticated attackers to perform privileged actions such as installing and activating plugins from attacker-supplied URLs, deleting plugins and themes, upgrading WordPress core, or logging in as an administrator via SSO. The vulnerability arises because sites not connected to the WPMU DEV Hub have an empty API key, making request signatures trivially forgeable. Version 5.0.0 also removed a replay check, increasing exploitability. Sites connected to a WPMU DEV account with a valid API key are not affected. Join the discussion | CVE Database V5 | 08/06/2026, 04:26:51 UTC Added: 08/06/2026, 05:41:47 UTC |
Showing 1 to 1 of 1 result