PT-2026-103717 · WordPress · Ultimate Multisite

·

CVE-2026-75957

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform versions prior to 2.15.1
Description An authentication bypass exists in the login customer after checkout function via the checkout form parameter. The issue occurs because the publicly accessible wu ajax nopriv wu validate form AJAX handler accepts a freely obtainable checkout nonce. When the checkout form parameter is set to wu-finish-checkout, the get validation rules() function discards all validation rules and finish checkout form fields() returns an empty step list, causing is last step() to return true. This routes the request directly to order processing, where maybe create customer() resolves an attacker-supplied email address to an existing WordPress user ID without authentication. Subsequently, login customer after checkout() executes wp set auth cookie() for that user ID through a passwordless path. This allows unauthenticated attackers to log in as any WordPress user, including a Network Super Admin, provided the target account has no pre-existing Ultimate Multisite customer record.
Recommendations Update the plugin to a version newer than 2.15.0. As a temporary mitigation, restrict access to the wu ajax nopriv wu validate form AJAX handler or avoid using the checkout form parameter in the affected function.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75957

Affected Products

Ultimate Multisite