PT-2026-103717 · WordPress · Ultimate Multisite
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform versions prior to 2.15.1
Description
An authentication bypass exists in the
login customer after checkout function via the checkout form parameter. The issue occurs because the publicly accessible wu ajax nopriv wu validate form AJAX handler accepts a freely obtainable checkout nonce. When the checkout form parameter is set to wu-finish-checkout, the get validation rules() function discards all validation rules and finish checkout form fields() returns an empty step list, causing is last step() to return true. This routes the request directly to order processing, where maybe create customer() resolves an attacker-supplied email address to an existing WordPress user ID without authentication. Subsequently, login customer after checkout() executes wp set auth cookie() for that user ID through a passwordless path. This allows unauthenticated attackers to log in as any WordPress user, including a Network Super Admin, provided the target account has no pre-existing Ultimate Multisite customer record.Recommendations
Update the plugin to a version newer than 2.15.0.
As a temporary mitigation, restrict access to the
wu ajax nopriv wu validate form AJAX handler or avoid using the checkout form parameter in the affected function.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ultimate Multisite