Authentication Bypass in The Ultimate Multisite WordPress Plugin
An authentication bypass vulnerability in The Ultimate Multisite plugin allows unauthenticated attackers to log in as any WordPress user, including administrators, by manipulating the AJAX checkout process.
CVE search metadata
CVE search record: CVE-2026-75957. Severity: critical. CVSS: 9.8. KEV: no. Product: The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform (<= 2.15.0). Brief: Authentication Bypass in The Ultimate Multisite WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-75957/
The Ultimate Multisite plugin for WordPress (versions 2.15.0 and earlier) contains a critical authentication bypass vulnerability (CVE-2026-75957). The flaw resides in the wu_ajax_nopriv_wu_validate_form AJAX handler, which fails to properly validate the checkout_form parameter and its associated nonce. By crafting a request that sets checkout_form=wu-finish-checkout, an attacker can bypass all validation rules and force the system to proceed directly to the maybe_create_customer() function.
This function fails to verify ownership or authentication when associating an attacker-provided email address with a WordPress user account. Subsequently, the login_customer_after_checkout() function calls wp_set_auth_cookie() to authenticate the attacker as the user corresponding to the provided email address. This allows an attacker to gain unauthorized access to any account, including Network Super Admins, provided that the target account does not already have a registered customer record within the plugin. This vulnerability poses a severe risk to WordPress Multisite environments.
Attack Chain
- Attacker identifies a target WordPress site running The Ultimate Multisite plugin version 2.15.0 or lower.
- Attacker obtains the target user's email address and a valid (but not necessarily authorized) checkout nonce.
- Attacker sends an HTTP POST request to the
wp-admin/admin-ajax.phpendpoint with the actionwu_validate_form. - Attacker includes the
checkout_form=wu-finish-checkoutparameter in the request payload to trigger the vulnerable code path. - The plugin's AJAX handler
wu_ajax_nopriv_wu_validate_formdiscards validation rules and bypasses the step list checks. - The
maybe_create_customer()function processes the supplied email and resolves it to a pre-existing WordPress user ID. - The
login_customer_after_checkout()function executeswp_set_auth_cookie()for the resolved user ID. - Attacker gains a session cookie and is granted full access to the target's account without providing a password.
Impact
Successful exploitation allows unauthenticated attackers to gain administrative access to WordPress Multisite installations. This can lead to total site compromise, data exfiltration, modification of network-wide settings, and the potential for lateral movement within the multisite environment by impersonating Network Super Admins.
Recommendation
- Immediately update The Ultimate Multisite plugin to a version patched beyond 2.15.0.
- Audit WordPress user logs for unexpected login events originating from the
admin-ajax.phpendpoint. - Review all user accounts for suspicious profile changes or unauthorized creation of customer records.
- Implement stricter access controls on AJAX endpoints if plugin-level patches are not immediately available.
Immediate actions
Upgrade The Ultimate Multisite plugin to version > 2.15.0
Mitigations
Patch plugin
CVE-2026-75957
Detection coverage 1
Detect CVE-2026-75957 Exploitation - Authentication Bypass Attempt
criticalDetects HTTP POST requests to the vulnerable WordPress AJAX handler with parameters indicative of the CVE-2026-75957 authentication bypass
Detection queries are available on the platform. Get full rules →