<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>The Ultimate Multisite – WordPress Multisite SaaS &amp; WaaS Platform (&lt;= 2.15.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/the-ultimate-multisite--wordpress-multisite-saas--waas-platform--2.15.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 08:39:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/the-ultimate-multisite--wordpress-multisite-saas--waas-platform--2.15.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in The Ultimate Multisite WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-75957/</link><pubDate>Thu, 01 Oct 2026 08:39:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-75957/</guid><description>An authentication bypass vulnerability in The Ultimate Multisite plugin allows unauthenticated attackers to log in as any WordPress user, including administrators, by manipulating the AJAX checkout process.</description><content:encoded><![CDATA[<p>The Ultimate Multisite plugin for WordPress (versions 2.15.0 and earlier) contains a critical authentication bypass vulnerability (CVE-2026-75957). The flaw resides in the <code>wu_ajax_nopriv_wu_validate_form</code> AJAX handler, which fails to properly validate the <code>checkout_form</code> parameter and its associated nonce. By crafting a request that sets <code>checkout_form=wu-finish-checkout</code>, an attacker can bypass all validation rules and force the system to proceed directly to the <code>maybe_create_customer()</code> function.</p>
<p>This function fails to verify ownership or authentication when associating an attacker-provided email address with a WordPress user account. Subsequently, the <code>login_customer_after_checkout()</code> function calls <code>wp_set_auth_cookie()</code> to authenticate the attacker as the user corresponding to the provided email address. This allows an attacker to gain unauthorized access to any account, including Network Super Admins, provided that the target account does not already have a registered customer record within the plugin. This vulnerability poses a severe risk to WordPress Multisite environments.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target WordPress site running The Ultimate Multisite plugin version 2.15.0 or lower.</li>
<li>Attacker obtains the target user's email address and a valid (but not necessarily authorized) checkout nonce.</li>
<li>Attacker sends an HTTP POST request to the <code>wp-admin/admin-ajax.php</code> endpoint with the action <code>wu_validate_form</code>.</li>
<li>Attacker includes the <code>checkout_form=wu-finish-checkout</code> parameter in the request payload to trigger the vulnerable code path.</li>
<li>The plugin's AJAX handler <code>wu_ajax_nopriv_wu_validate_form</code> discards validation rules and bypasses the step list checks.</li>
<li>The <code>maybe_create_customer()</code> function processes the supplied email and resolves it to a pre-existing WordPress user ID.</li>
<li>The <code>login_customer_after_checkout()</code> function executes <code>wp_set_auth_cookie()</code> for the resolved user ID.</li>
<li>Attacker gains a session cookie and is granted full access to the target's account without providing a password.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain administrative access to WordPress Multisite installations. This can lead to total site compromise, data exfiltration, modification of network-wide settings, and the potential for lateral movement within the multisite environment by impersonating Network Super Admins.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update The Ultimate Multisite plugin to a version patched beyond 2.15.0.</li>
<li>Audit WordPress user logs for unexpected login events originating from the <code>admin-ajax.php</code> endpoint.</li>
<li>Review all user accounts for suspicious profile changes or unauthorized creation of customer records.</li>
<li>Implement stricter access controls on AJAX endpoints if plugin-level patches are not immediately available.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>authentication-bypass</category><category>cve</category></item></channel></rss>