PatchSiren

Ultimate Multisite CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Ultimate Multisite CVE published 2026-10-08

CVE-2026-103646

The Ultimate Multisite WordPress plugin before 2.17.0 has an unauthenticated authentication bypass vulnerability via the 'email_address' parameter. This allows an attacker to log in as any existing user, including a Network Super Admin, if they know the user's email address. The vulnerability exists in Ultimate Multisite WordPress plugin versions before 2.17.0 and requires a checkout form configured witho [truncated]