External risk intelligence

Ultimate Multisite WordPress Plugin Authentication Bypass Leading to Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-75957

The vulnerability exists in a WordPress plugin designed for Multisite SaaS and WaaS platforms. These platforms are web-based services intended to be publicly accessible to end users, and the vulnerable AJAX handler is explicitly noted as a public endpoint, making the attack surface commonly internet-facing.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Ultimate Multisite plugin for WordPress, which is used for managing WordPress Multisite as a Service. This issue allows unauthenticated attackers, who know a user's email address, to bypass authentication and log in as that user, potentially including high-privilege administrators. The main concern is confirming if this plugin is in use and if the affected user accounts are exposed.

  • Unauthenticated attackers can impersonate users.
  • Affects WordPress Multisite platforms and their administrators.
  • Confirm if the plugin is used and users are exposed.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication in the Ultimate Multisite plugin by exploiting a flaw in how it processes checkout form parameters. By sending a specific request to a publicly accessible AJAX handler, an attacker can trick the plugin into skipping its usual validation and security checks. This allows them to process an order and then log in as any existing user, including a super administrator, without needing a password. This is possible if the target user account doesn't have a pre-existing customer record within the plugin.

  • Publicly accessible AJAX handler.
  • Checkout form parameter bypasses validation.
  • Unauthenticated login as any user.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to log in as any existing WordPress user, including a Network Super Admin, by knowing their email address. This is possible when the targeted user account lacks a pre-existing customer record within the Ultimate Multisite plugin, such as a Network Super Admin on a newly installed Multisite, or an administrator added before the plugin was configured.

  • WordPress user accounts
  • Bypass authentication via `checkout_form` parameter
  • Unauthorized administrative access

Operational Fix

Recommended remediation, mitigation, and detection steps

The WordPress Multisite plugin requires immediate attention from platform and application owners. The first step is to identify all WordPress instances using this plugin, determine their exposure to the internet, and confirm ownership for each. Subsequently, a plan for remediation or risk reduction should be developed based on the criticality and accessibility of each instance.

  • Platform and application owners should lead remediation.
  • Verify plugin installation and external accessibility.
  • Plan urgent updates or implement controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Ultimate Multisite plugin?

Ultimate Multisite is a WordPress extension designed to transform a standard WordPress installation into a SaaS (Software as a Service) or WaaS (Website as a Service) platform. It provides tools for managing network-wide user signups, subscriptions, and custom checkout flows, allowing site owners to host multiple client sites or services from a single WordPress multisite environment.

What is the weakness class for CVE-2026-75957?

This vulnerability is classified as Improper Authentication (CWE-287). In plain terms, the plugin fails to verify the identity of a person attempting to log in. By manipulating specific checkout parameters, the system is tricked into skipping its security checks, allowing an attacker to bypass the password requirement and authenticate as any existing user on the network.

How can an attacker trigger this vulnerability?

An attacker targets a public AJAX handler within the plugin, submitting a crafted request that uses the 'checkout_form' parameter to suppress validation rules. This trick forces the plugin to treat the request as a finished, valid order. Crucially, this does not work if the target user already has a customer record associated with the plugin; it specifically affects accounts, such as Network Super Admins, that lack these internal records.

Is this vulnerability relevant to my environment?

Because this flaw exists in a public-facing AJAX handler designed for user registrations and checkouts, Halo Surface Signal identifies the attack surface as commonly internet-facing. If you host a public WordPress Multisite platform using this plugin, your system is likely reachable by unauthorized external actors, making it a high priority for review.

What are the first steps to address this CVE?

Begin by auditing your WordPress network to verify if the Ultimate Multisite plugin is installed and active. Determine which instances are accessible via the internet. Once identified, prioritize these instances for updates or mitigation, as they are the primary targets for exploitation. Ensure you are tracking all affected administrative accounts that may be vulnerable to impersonation.

References