CPE
An authentication bypass vulnerability in The Ultimate Multisite plugin allows unauthenticated attackers to log in as any WordPress user, including administrators, by manipulating the AJAX checkout process.