CVE-2026-16051Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote code execution).

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-12); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-12: 2Mentions · 2026-08-14: 1Mentions · 2026-08-20: 1Active Exploitation · 2026-08-14: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-20: 108-1208-1408-20
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
Patch
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-122
Disclosure2
2026-08-141
Active Exploitation1
2026-08-201
Patch1
Full discourse4 posts
  • Avery J. Parker@averyjparker
    Patch

    Named bug, not vibes. WPMU DEV Dashboard through 5.0.0 (CVE-2026-15459 / CVE-2026-16051): unauthenticated Hub actions, including installing a plugin. That's remote code execution. Patch is 5.0.1. If the site was already popped, the patch does not pull the injector out of the files or t

    Post summary

    The content describes RCE vulnerabilities (CVE‑2026‑15459/CVE‑2026‑16051) in WPMU DEV Dashboard, highlights the required patch 5.0.1, and notes that the patch does not remove the injector if already installed.

    3000042
    97 followersView on X
  • S.A. Lowell@sa_lowell
    Active Exploitation

    CVE-2026-16051 completely fucked one of my client's servers. The plugin was left over from the original dev years and years ago and I never did an audit of what plugins were left over and no longer needed. The main app that I work on is separate from Wordpress so I pretty much never go into that side of it, but it's on the same server. Honestly, without Claude it would have easily taken me *days* to sift through everything and make sure it was all removed or completely boot up a fresh new server (Which would hilariously have been the easier + faster route, but looking through all the dynamic/upload stuff that users can manage on their own would have been a fucking pain.) But with Claude it took just a few hours of casual oversight from me which also means I was able to fuck off and do other stuff.

    Post summary

    The user reports having suffered an active exploitation of CVE-2026-16051 on a client server, but offers no technical detail, PoC, or patch information.

    0000045
    120 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-16051 The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those r… https://www.cve.org/CVERecord?id=CVE-2026-16051 ----- Traducción: CVE-2026-16051 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-16051, noting that the wpmudev-updates plugin version 5.0.1 and earlier fails to verify package integrity via its remote interface, but it provides no PoC, exploit code, active exploitation claim, or patch details.

    0000026
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-16051 The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those r… https://www.cve.org/CVERecord?id=CVE-2026-16051

    Post summary

    The post cites CVE-2026-16051, noting a lack of integrity verification in the wpmudev-updates plugin before version 5.0.1, but provides no further technical detail, PoC, exploitation evidence, or remedy.

    000001.0K
    57.9K followersView on X

Explore more