CVE-2026-103646
Received Received - Intake

Unauthenticated Account Takeover in Ultimate Multisite WordPress Plugin

Vulnerability report for CVE-2026-103646, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: WPScan

Description

The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, including a Network Super Admin, whose email address they know. This bypass is not addressed by the 2.15.1 fix for CVE-2026-75957 and remains exploitable in all versions up to and including 2.16.1, the releases that fix was expected to cover. Exploitation requires a checkout form configured without a password field (auto-generated password) and a target account that has no existing customer record in the Ultimate Multisite WordPress plugin before 2.17.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Ultimate Multisite 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated authentication bypass in the Ultimate Multisite WordPress plugin before version 2.17.0. An attacker can log in as any existing user, including a Network Super Admin, by submitting an email address that matches an existing account. The vulnerability occurs because the plugin links a logged-out checkout to an existing account without authentication and normalizes email addresses inconsistently during checks.

Detection Guidance

Check if the Ultimate Multisite WordPress plugin version is below 2.17.0. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version details. Look for checkout forms without password fields and accounts with no existing customer records in the plugin.

Impact Analysis

An attacker could gain unauthorized access to any WordPress account with a known email address, including high-privilege accounts like Network Super Admins. This could lead to data theft, unauthorized changes, or complete site compromise if the attacker exploits the account.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. Organizations using the affected plugin may face compliance breaches, legal penalties, and reputational damage due to compromised user accounts.

Mitigation Strategies

Immediately update the Ultimate Multisite WordPress plugin to version 2.17.0 or later. Disable checkout forms without password fields if possible. Review user accounts for unauthorized access and reset passwords for accounts that may have been compromised.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103646. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart