Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in the Ultimate Multisite plugin for WordPress, which is used for managing WordPress Multisite as a Service. This issue allows unauthenticated attackers, who know a user's email address, to bypass authentication and log in as that user, potentially including high-privilege administrators. The main concern is confirming if this plugin is in use and if the affected user accounts are exposed.
- Unauthenticated attackers can impersonate users.
- Affects WordPress Multisite platforms and their administrators.
- Confirm if the plugin is used and users are exposed.
Attack Path
How an attacker could exploit the issue
An attacker can bypass authentication in the Ultimate Multisite plugin by exploiting a flaw in how it processes checkout form parameters. By sending a specific request to a publicly accessible AJAX handler, an attacker can trick the plugin into skipping its usual validation and security checks. This allows them to process an order and then log in as any existing user, including a super administrator, without needing a password. This is possible if the target user account doesn't have a pre-existing customer record within the plugin.
- Publicly accessible AJAX handler.
- Checkout form parameter bypasses validation.
- Unauthenticated login as any user.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated attacker to log in as any existing WordPress user, including a Network Super Admin, by knowing their email address. This is possible when the targeted user account lacks a pre-existing customer record within the Ultimate Multisite plugin, such as a Network Super Admin on a newly installed Multisite, or an administrator added before the plugin was configured.
- WordPress user accounts
- Bypass authentication via `checkout_form` parameter
- Unauthorized administrative access
Operational Fix
Recommended remediation, mitigation, and detection steps
The WordPress Multisite plugin requires immediate attention from platform and application owners. The first step is to identify all WordPress instances using this plugin, determine their exposure to the internet, and confirm ownership for each. Subsequently, a plan for remediation or risk reduction should be developed based on the criticality and accessibility of each instance.
- Platform and application owners should lead remediation.
- Verify plugin installation and external accessibility.
- Plan urgent updates or implement controls.