CVE-2026-75957: Authentication Bypass in Ultimate Multisite
This text was generated using artificial intelligence (AI).CVE-2026-75957 affects the WordPress plugin Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform up to and including version 2.15.0. According to Wordfence, the vulnerability allows unauthenticated attackers to log in as existing WordPress users, provided their email address is known and there is no Ultimate Multisite customer record for the account.
A patch for the vulnerability is available starting from version 2.15.1 , which has been available since August 19, 2026.
Fixed version: 2.15.1 (available since August 19, 2026)
Check focus: WordPress accounts without Ultimate Multisite customer record
How the authentication bypass occurs
According to Wordfence, the cause lies in the checkout process of the plugin. A publicly accessible AJAX handler accepts a checkout nonce. Through the parameter checkout_form , the form processing can be manipulated to discard its validation rules and treat the checkout as completed.
Then, the function maybe_create_customer assigns a submitted email address to an existing WordPress user ID. No check of the login or account ownership is performed. The function login_customer_after_checkout then sets an authentication cookie for this user ID via a passwordless process.
This allows unauthenticated attackers to log in as existing WordPress users. According to Wordfence, this also includes a Network Super Admin if no Ultimate Multisite customer record exists for the respective account. An compromised Network Super Admin account controls the entire multisite network and can install plugins and themes – thereby usually allowing code execution on the server.
Which accounts should be particularly checked
The vulnerability does not affect every account under the same conditions. What matters is whether a customer record in Ultimate Multisite already exists for the respective WordPress identity.
Particularly relevant are:
Network Super Admins in a freshly set up multisite installation
Administrators or editors created before the setup of Ultimate Multisite
Other existing WordPress accounts without an Ultimate Multisite customer record
Active exploitation of CVE-2026-75957 is not documented.
Relevance for Organizations in Germany, Austria, and Switzerland
If CVE-2026-75957 is exploited, attackers can take over existing WordPress accounts and thereby gain access to stored data, possibly including personal customer data. If an organization in the EU detects such an account takeover, it must verify whether a reportable data breach according to Art. 33 GDPR is present; the 72-hour deadline begins upon knowledge of the breach. Operators falling under NIS-2 or national implementation law should assess the vulnerability as part of their risk management. In Switzerland, operators of critical infrastructures are subject to the reporting obligation for cyberattacks to BACS according to ISG.
Apply the patch and check for impact
The immediate action is the update to version 2.15.1 or higher. The patch has been available since August 19, 2026; the WordPress plugin SVN documents the changes between versions 2.15.0 and 2.15.1.
The following steps are recommended for technical processing:
Record WordPress multisite installations with Ultimate Multisite.
Prioritize installations up to and including version 2.15.0.
Apply the patch to version 2.15.1 or higher.
Check which WordPress accounts do not have an Ultimate Multisite customer record.
Examine logins of administrators and Network Super Admins as well as newly created Ultimate Multisite customer records for existing accounts for anomalies.
Document patch status and impact of the systems.
Establish continuous vulnerability and vendor risk monitoring.
The check should include the used plugin version, the publicly accessible AJAX endpoint, and the account structure.
Capture externally accessible WordPress systems
Ultimate Multisite is typically operated on publicly accessible WordPress multisite installations, often under customer domains. LocateRisk EASM makes externally accessible WordPress systems and identifiable software visible under their own domains.
However, an externally determined plugin fingerprint does not alone prove a specifically vulnerable installation. For CVE-2026-75957, it is additionally relevant whether an affected version is in use and whether WordPress accounts without an Ultimate Multisite customer record are present.
The external detection of publicly accessible WordPress systems supports the technical inventory. The patch assessment and the review of the account structure take place in their respective system context.
Am I affected?
This affects Ultimate Multisite in the versions mentioned above; the vulnerability was fixed in 2.15.1. If you want to know whether Ultimate Multisite is visible in your externally accessible infrastructure, you can check the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
The specifically installed version cannot always be determined from the outside — the match with the Wordfence advisory is crucial.
CVE-2026-75957 allows unauthenticated attackers to log in as any existing WordPress user – including a Network Super Admin – by only knowing the email address of the target account. A prerequisite is that there is no Ultimate-Multisite customer record for the account in question.
All versions of the plugin up to and including are affected. 2.15.0. The issue was fixed in version 2.15.1 which has been available since August 19, 2026. Installations should be updated to 2.15.1 or higher immediately.
Accounts are at risk for which no customer record has yet been created in Ultimate Multisite. This particularly includes Network Super Admins on newly set up Multisite installations, as well as Administrators and Editors that were created before the configuration of the plugin.
Status: October 01, 2026. This article is for general informational purposes and is not legal, security, or action advice for individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always decisive. Despite careful research, we do not guarantee the timeliness, accuracy, or completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-75957
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.