A critical authentication bypass in the Ultimate Multisite plugin for WordPress, versions up to and including 2.15.0, can let an unauthenticated attacker log in as an existing WordPress user by supplying that user's email address. The attack works only against accounts that have no existing Ultimate Multisite customer record. According to the NVD description, that can include a Network Super Admin on a fresh Multisite install.
What Is It
CVE-2026-75957 is an authentication bypass (CWE-287) in the Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin. The flaw is in the checkout_form parameter of the login_customer_after_checkout function.
According to the NVD description, the publicly accessible wu_ajax_nopriv_wu_validate_form AJAX handler accepts a checkout nonce that anyone can obtain. Supplying checkout_form=wu-finish-checkout makes get_validation_rules() discard all validation rules, and finish_checkout_form_fields() returns an empty step list. This forces is_last_step() to return true, so the request goes straight into full order processing. maybe_create_customer() then matches the attacker-supplied email_address to an existing WordPress user ID without checking authentication or ownership. Finally, login_customer_after_checkout() calls wp_set_auth_cookie() for that user through a passwordless code path.
Why It Matters
NVD lists a CVSS 3.1 base score of 9.8 (CRITICAL), vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The attack works over the network, has low complexity, and needs no privileges or user interaction. An attacker who logs in as a Network Super Admin gets administrative control of the whole Multisite network.
One condition limits exploitation: the targeted account must have no existing Ultimate Multisite customer record. The description says this condition is met by a Network Super Admin on a fresh Multisite install and by any administrator or editor added before Ultimate Multisite was configured.
This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog, so KEV does not confirm active exploitation at this time. The NVD record status is "Deferred."
What's Vulnerable
- Vendor: superdav42
- Product: Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform
- Affected versions: all versions up to and including 2.15.0
Patch Status
The vulnerability affects versions through 2.15.0. NVD references link to a trunk changeset to class-checkout.php (changeset 3653622) and to a diff between the 2.15.0 and 2.15.1 tags, which points to a fix in 2.15.1. Administrators should update past 2.15.0 and check the Wordfence advisory for confirmed fixed-version details. CISA has not issued a KEV required action because there is no KEV entry.