Impact
Ultimate Multisite versions up to 2.15.0 allow an attacker to log in as any existing WordPress user without prior authentication. The flaw originates from the publicly accessible AJAX handler wu_ajax_nopriv_wu_validate_form, which accepts a checkout nonce and a checkout_form parameter that disables required validation and step checks. This path ultimately resolves an attacker‑supplied email address to a WordPress user ID and calls wp_set_auth_cookie() through a passwordless code path, producing a valid login session. The consequence is full access to the affected user account, potentially including network‑level privileges such as Super Admin. This represents a serious loss of confidentiality, integrity, and availability for the WordPress network. The vulnerability is a classic example of weak authentication and authorization controls, classified as CWE-287.
Affected Systems
WordPress sites that have installed the Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin from superdav42, version 2.15.0 or earlier. The flaw applies to any network where the plugin is enabled, regardless of site count or user roles, and can be exploited against any user account that does not already have an Ultimate Multisite customer record, such as Network Super Admins, administrators, or editors added before the plugin was activated.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. Because the EPSS score is not provided, the likelihood of exploitation cannot be precisely quantified, but the vulnerability is listed in the CISA KEV catalog as not yet included. Exploitation requires no pre-existing customer record for the target user; an attacker can craft an AJAX request that sets checkout_form to wu‑finish‑checkout, supplies a valid nonce, and specifies the victim’s email address. The order processing logic bypasses authentication, resolves the email to the user ID, and issues a session cookie. The attack path is straightforward and does not require any special privileges, making it a high‑risk, high‑impact threat for affected WordPress networks.
OpenCVE Enrichment