Impact
The wpmudev-updates WordPress plugin fails to validate the integrity of packages installed through its remote management interface and does not guard these requests against replay attacks, enabling an attacker who can obtain or replay a valid signed request to install and execute arbitrary code. This flaw gives the attacker full control over the affected system, compromising confidentiality, integrity, and availability. The weakness is an improper control of code generation (CWE-94).
Affected Systems
Any WordPress installation running the wpmudev-updates plugin with a version prior to 5.0.1 is affected. No vendor or product name beyond the plugin identifier is known, and version information is limited to the pre‑5.0.1 cutoff.
Risk and Exploitability
Based on the description, it is inferred that the exploit requires an attacker to obtain or replay a valid signed request, so the attack vector is likely local or network-based access to the remote management interface. This necessitates either privileged local access or an ability to intercept traffic. The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, yet its remote code execution nature denotes a high severity.
OpenCVE Enrichment