Impact
The wpmudev-updates WordPress plugin fails to validate the integrity of packages installed through its remote management interface and does not guard these requests against replay attacks, enabling an attacker who can obtain or replay a valid signed request to install and execute arbitrary code. This flaw gives the attacker full control over the affected system, compromising confidentiality, integrity, and availability. The weakness is a failure to verify cryptographic signatures (CWE-347) and the lack of replay protection (CWE-354).
Affected Systems
Any WordPress installation running the wpmudev-updates plugin with a version prior to 5.0.1 is affected. No vendor or product name beyond the plugin identifier is known, and version information is limited to the pre‑5.0.1 cutoff.
Risk and Exploitability
Because the exploit hinges on obtaining or replaying a signed request, an attacker must have access to the remote management interface or be able to intercept traffic; these conditions are typically met by local users with management privileges or by an attacker with network access to the site. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the nature of the flaw (remote code execution) indicates a high severity. Official remediation by the vendor is required to mitigate this risk.
OpenCVE Enrichment