WPMU Ldap Authentication

WPMU Ldap Authentication has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for WPMU Ldap Authentication has a vendor fix available, so running the current release closes it.

All of these findings were reported by Nguyen Xuan Chien. WPMU Ldap Authentication is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WPMU Ldap Authentication vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2025-48343

WPMU Ldap Authentication <= 5.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv5.1

WPMU Ldap Authentication

Aaron Axelsen

Author

Aaron Axelsen

4.3(3)
86/100
Last Updated
2025-12-29 (9mo ago)
Active Installs
60+
Downloads
13,923
Requires WP
5.2+
Requires PHP
7.4+
Tested up to
WP 6.8.8
Created
2012-06-13 (15y ago)

LDAP authentication is configured on a site-wide (as opposed to per-blog) level, so only Network Admin accounts have access to the configuration to LDAP connection information. Please make sure you have PHP compiled with LDAP support. This will show up as an LDAP section in your phpinfo() if it is correct. Remember – all the code for the plugin was contributed by volunteers, and you can show your gratitude by giving back to the community! How It Works When enabled, this plugin can automatically create WordPress user accounts and blogs for LDAP-authenticated users. Assuming user credentials authenticate against the LDAP server, creating local accounts and blogs follows this algorithm: Create a new WPMU User, with LDAP username and a randomly generated password. Some user information, such as first and last name, is extracted from the information returned from the LDAP server. Actions for user creation and activation are triggered. The user’s domain / URL are created depending on plugin configuration (i.e., VHost vs SubDir). If the option is set, a blog is created, with path and name based on the LDAP username and the blog is activated with the user being Administrator, and appropriate actions are triggered. It should be noted that even though a random password is created for a user (for WPMU accounts), it is never displayed to the user. This is intentional so that there is no confusion as to which password should be used; it will always be using LDAP credentials. As a result, though, if ever LDAP is disabled or if the server is unavailable, users created with LDAP authentication will be unable to log in unless their passwords are reset.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C