{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/the-ultimate-multisite--wordpress-multisite-saas--waas-platform--2.15.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wp-ultimate-multisite:the_ultimate_multisite:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-75957"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Ultimate Multisite – WordPress Multisite SaaS \u0026 WaaS Platform (\u003c= 2.15.0)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","authentication-bypass","cve"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Ultimate Multisite plugin for WordPress (versions 2.15.0 and earlier) contains a critical authentication bypass vulnerability (CVE-2026-75957). The flaw resides in the \u003ccode\u003ewu_ajax_nopriv_wu_validate_form\u003c/code\u003e AJAX handler, which fails to properly validate the \u003ccode\u003echeckout_form\u003c/code\u003e parameter and its associated nonce. By crafting a request that sets \u003ccode\u003echeckout_form=wu-finish-checkout\u003c/code\u003e, an attacker can bypass all validation rules and force the system to proceed directly to the \u003ccode\u003emaybe_create_customer()\u003c/code\u003e function.\u003c/p\u003e\n\u003cp\u003eThis function fails to verify ownership or authentication when associating an attacker-provided email address with a WordPress user account. Subsequently, the \u003ccode\u003elogin_customer_after_checkout()\u003c/code\u003e function calls \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e to authenticate the attacker as the user corresponding to the provided email address. This allows an attacker to gain unauthorized access to any account, including Network Super Admins, provided that the target account does not already have a registered customer record within the plugin. This vulnerability poses a severe risk to WordPress Multisite environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site running The Ultimate Multisite plugin version 2.15.0 or lower.\u003c/li\u003e\n\u003cli\u003eAttacker obtains the target user's email address and a valid (but not necessarily authorized) checkout nonce.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP POST request to the \u003ccode\u003ewp-admin/admin-ajax.php\u003c/code\u003e endpoint with the action \u003ccode\u003ewu_validate_form\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker includes the \u003ccode\u003echeckout_form=wu-finish-checkout\u003c/code\u003e parameter in the request payload to trigger the vulnerable code path.\u003c/li\u003e\n\u003cli\u003eThe plugin's AJAX handler \u003ccode\u003ewu_ajax_nopriv_wu_validate_form\u003c/code\u003e discards validation rules and bypasses the step list checks.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003emaybe_create_customer()\u003c/code\u003e function processes the supplied email and resolves it to a pre-existing WordPress user ID.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003elogin_customer_after_checkout()\u003c/code\u003e function executes \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e for the resolved user ID.\u003c/li\u003e\n\u003cli\u003eAttacker gains a session cookie and is granted full access to the target's account without providing a password.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain administrative access to WordPress Multisite installations. This can lead to total site compromise, data exfiltration, modification of network-wide settings, and the potential for lateral movement within the multisite environment by impersonating Network Super Admins.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update The Ultimate Multisite plugin to a version patched beyond 2.15.0.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user logs for unexpected login events originating from the \u003ccode\u003eadmin-ajax.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eReview all user accounts for suspicious profile changes or unauthorized creation of customer records.\u003c/li\u003e\n\u003cli\u003eImplement stricter access controls on AJAX endpoints if plugin-level patches are not immediately available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T08:39:35Z","date_published":"2026-10-01T08:39:35Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-75957/","summary":"An authentication bypass vulnerability in The Ultimate Multisite plugin allows unauthenticated attackers to log in as any WordPress user, including administrators, by manipulating the AJAX checkout process.","title":"Authentication Bypass in The Ultimate Multisite WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-75957/"}],"language":"en","title":"CraftedSignal Threat Feed - The Ultimate Multisite – WordPress Multisite SaaS \u0026 WaaS Platform (\u003c= 2.15.0)","version":"https://jsonfeed.org/version/1.1"}