CRITICAL
9.8 CVE-2026-103646 Published 8 Oct 2026
Ultimate Multisite WordPress Plugin Authentication Bypass Vulnerability
Worried this affects your website?
The Ultimate Multisite WordPress plugin before 2.17.0 contains an authentication bypass that lets an unauthenticated attacker log in as any existing user, including a Network Super Admin, if the attacker knows the target's email address.
During logged-out checkout, the plugin links the order to an existing WordPress account matching the submitted email and logs the attacker in. The duplicate-account check normalizes the address differently from the lookup used to create the customer, enabling the bypass.
This flaw is not fixed by the 2.15.1 patch for CVE-2026-75957 and remains exploitable in all versions up to and including 2.16.1. Exploitation requires:
- A checkout form configured without a password field (auto-generated password)
- A target account with no existing customer record in the plugin before 2.17.0
Reference: CVE-2026-103646 on NVD
← Back to Security News