CVE-2026-75957: Authentication Bypass in Ultimate Multisite

This text was generated using artificial intelligence (AI).CVE-2026-75957 affects the WordPress plugin Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform up to and including version 2.15.0. According to Wordfence, the vulnerability allows unauthenticated attackers to log in as existing WordPress users, provided their email address is known and there is no Ultimate Multisite customer record for the account.

A patch for the vulnerability is available starting from version 2.15.1 , which has been available since August 19, 2026.

Are my systems affected? Check now →