Sceawere

Vulnerability Detail

CVE-2026-103646UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ultimate Multisite Authentication Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
8h ago
Vendor
Unknown
Product
Ultimate Multisite
Attack Type
CWE-287 Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, including a Network Super Admin, whose email address they know. This bypass is not addressed by the 2.15.1 fix for CVE-2026-75957 and remains exploitable in all versions up to and including 2.16.1, the releases that fix was expected to cover. Exploitation requires a checkout form configured without a password field (auto-generated password) and a target account that has no existing customer record in the Ultimate Multisite WordPress plugin before 2.17.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-08T06:16:37.957Z",
  "pubdate": "2026-10-08T06:16:37.957Z",
  "executiveSummary": "The Ultimate Multisite WordPress plugin contains a critical authentication bypass vulnerability that allows unauthenticated attackers to hijack existing WordPress accounts, including those with Network Super Admin privileges.\nThe flaw stems from improper input validation and normalization during the guest checkout process, enabling an attacker to force an account linkage between their session and a victim's email address.\nThis vulnerability is particularly severe as it bypasses previous security patches, specifically affecting versions up to and including 2.16.1.\nSuccessful exploitation requires knowledge of the target's email address and specific checkout configurations, such as the absence of a password field. Once exploited, an attacker gains full access to the target's account, leading to complete site compromise, data exfiltration, or unauthorized administrative actions.\nThe risk implication is extreme given that the vulnerability allows for privilege escalation to the highest possible authority within a WordPress multisite network without requiring any prior authentication or valid credentials.",
  "technicalDetails": "The vulnerability resides within the Ultimate Multisite plugin's customer account management and checkout logic, specifically how it handles the linkage between unauthenticated guest checkouts and existing WordPress user accounts.\nThe root cause is a dual-failure in authentication logic: first, the plugin fails to mandate authentication before linking a checkout session to a WordPress user; second, a discrepancy exists in how the plugin performs email address normalization during the duplicate-account check versus the lookup process utilized during customer creation.\nBecause the input normalization is inconsistent, an attacker can supply an email address that the system perceives as valid for an existing user account, effectively overriding or bypassing the logic intended to prevent account duplication or unauthorized linkage.\nExploitation is contingent upon the checkout form being configured to utilize auto-generated passwords rather than explicit user-provided authentication fields. When an attacker provides a known email address associated with an existing user, the plugin matches the request to that specific user record.\nThe attack flow proceeds as follows: 1) The attacker navigates to the checkout page configured for auto-generated passwords. 2) The attacker enters the target victim's email address. 3) Due to the normalization mismatch, the plugin fails to detect that the user already exists in a restricted capacity or incorrectly associates the checkout session with the legitimate user's profile. 4) The system automatically logs the attacker into the account associated with that email address. 5) If the target account is a Network Super Admin, the attacker inherits full administrative privileges.\nThis mechanism bypasses the previous partial fix implemented in version 2.15.1 for CVE-2026-75957, confirming that the underlying logic flaws remained unaddressed in all versions up to and including 2.16.1. The attack is executable over the network without any interaction from the victim beyond the existence of their account. Post-exploitation, the attacker maintains authenticated access to the target's session, enabling full control over the account and the associated multisite infrastructure."
}
CVE-2026-103646: Ultimate Multisite Authentication Bypass (CRITICAL Severity, CVSS: 9.8) | Sceawere