Authentication Bypass in Ultimate Multisite Plugin for WordPress by Ultimate Member
CVE-2026-103646
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 8 October 2026
Badges
What is CVE-2026-103646?
The Ultimate Multisite Plugin for WordPress, prior to version 2.17.0, contains a significant vulnerability that allows unauthenticated attackers to log into existing user accounts, including those of Network Super Admins. This exploit occurs when a checkout form is utilized without a password field, permitting the attacker to bypass normal authentication procedures. The normalizing process applied to email addresses during duplicate account checks can lead to inconsistencies, allowing an attacker who knows a valid email address to gain unauthorized access. This issue persists in all versions up to 2.16.1 despite prior patches intended to address associated vulnerabilities. As a result, users of the plugin are urged to update to the latest version immediately to mitigate this risk.
Affected Version(s)
Ultimate Multisite 0 < 2.17.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.