Executive brief
Defender Security is a WordPress security plugin used to protect WordPress sites. In multisite deployments, a site administrator (a less-privileged role) could exploit an improperly restricted network-wide setting to install malicious code that runs with the privileges of the entire WordPress network, affecting all sites simultaneously and potentially leading to data theft, defacement, or ransomware deployment.
Technical details
The vulnerability is a privilege escalation and arbitrary code execution flaw in the Hub Connector functionality. A site administrator on a WordPress multisite network can mint a network-wide authentication credential through a subsite connection screen belonging to a sibling WPMUDEV plugin, then use that credential to invoke a remote command channel (keyed via HMAC-SHA256 authentication) that accepts plugin installation requests. The attack requires the multisite to not yet be connected to WPMUDEV's hub service (the default state for the free plugin) and the presence of a sibling WPMUDEV plugin on the attacker's subsite to generate the necessary callback nonce. Once the credential is set network-wide, an attacker can install and activate arbitrary plugins across the entire network without further authentication. The vulnerability is fixed in version 6.2.0.
Affected products
- WPMUDEV Defender Security before 6.2.0
Timeline
- 2026-08-25: disclosed
- 2026-08-27: patched