Skip to content
Threat Feed
critical advisory

Authentication Bypass in The Ultimate Multisite WordPress Plugin

An authentication bypass vulnerability in The Ultimate Multisite plugin allows unauthenticated attackers to log in as any WordPress user, including administrators, by manipulating the AJAX checkout process.

CVE search metadata

CVE search record: CVE-2026-75957. Severity: critical. CVSS: 9.8. KEV: no. Product: The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform (<= 2.15.0). Brief: Authentication Bypass in The Ultimate Multisite WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-75957/

The Ultimate Multisite plugin for WordPress (versions 2.15.0 and earlier) contains a critical authentication bypass vulnerability (CVE-2026-75957). The flaw resides in the wu_ajax_nopriv_wu_validate_form AJAX handler, which fails to properly validate the checkout_form parameter and its associated nonce. By crafting a request that sets checkout_form=wu-finish-checkout, an attacker can bypass all validation rules and force the system to proceed directly to the maybe_create_customer() function.

This function fails to verify ownership or authentication when associating an attacker-provided email address with a WordPress user account. Subsequently, the login_customer_after_checkout() function calls wp_set_auth_cookie() to authenticate the attacker as the user corresponding to the provided email address. This allows an attacker to gain unauthorized access to any account, including Network Super Admins, provided that the target account does not already have a registered customer record within the plugin. This vulnerability poses a severe risk to WordPress Multisite environments.

Attack Chain

  1. Attacker identifies a target WordPress site running The Ultimate Multisite plugin version 2.15.0 or lower.
  2. Attacker obtains the target user's email address and a valid (but not necessarily authorized) checkout nonce.
  3. Attacker sends an HTTP POST request to the wp-admin/admin-ajax.php endpoint with the action wu_validate_form.
  4. Attacker includes the checkout_form=wu-finish-checkout parameter in the request payload to trigger the vulnerable code path.
  5. The plugin's AJAX handler wu_ajax_nopriv_wu_validate_form discards validation rules and bypasses the step list checks.
  6. The maybe_create_customer() function processes the supplied email and resolves it to a pre-existing WordPress user ID.
  7. The login_customer_after_checkout() function executes wp_set_auth_cookie() for the resolved user ID.
  8. Attacker gains a session cookie and is granted full access to the target's account without providing a password.

Impact

Successful exploitation allows unauthenticated attackers to gain administrative access to WordPress Multisite installations. This can lead to total site compromise, data exfiltration, modification of network-wide settings, and the potential for lateral movement within the multisite environment by impersonating Network Super Admins.

Recommendation

  • Immediately update The Ultimate Multisite plugin to a version patched beyond 2.15.0.
  • Audit WordPress user logs for unexpected login events originating from the admin-ajax.php endpoint.
  • Review all user accounts for suspicious profile changes or unauthorized creation of customer records.
  • Implement stricter access controls on AJAX endpoints if plugin-level patches are not immediately available.

Immediate actions

Upgrade The Ultimate Multisite plugin to version > 2.15.0

IT Operations 24h

Mitigations

Patch plugin

immediate IT Operations

CVE-2026-75957

Detection coverage 1

Detect CVE-2026-75957 Exploitation - Authentication Bypass Attempt

critical

Detects HTTP POST requests to the vulnerable WordPress AJAX handler with parameters indicative of the CVE-2026-75957 authentication bypass

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →