Review
Ultimate Multisite
CVE published 2026-10-08
CVE-2026-103646
The Ultimate Multisite WordPress plugin before 2.17.0 has an unauthenticated authentication bypass vulnerability via the 'email_address' parameter. This allows an attacker to log in as any existing user, including a Network Super Admin, if they know the user's email address. The vulnerability exists in Ultimate Multisite WordPress plugin versions before 2.17.0 and requires a checkout form configured witho [truncated]