Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103646— Ultimate Multisite < 2.17.0 - Unauthenticated Authentication Bypass via 'email_address' Parameter

Quick assessment

Affected
Unknown Ultimate Multisite
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ultimate Multisite WordPress 插件在 2.17.0 版本之前存在安全漏洞。该漏洞允许未认证的攻击者在注销结账流程中,将结账会话链接到并登录为与提交的电子邮件地址匹配的现有 WordPress 账户。由于该插件在重复账户检查时对电子邮件地址的规范化处理方式与创建客户记录时的查找方式不一致,攻击者可以通过已知邮箱地址以任意现有用户(包括网络超级管理员)的身份登录。 此绕过问题并未被 CVE-2026-75957 在 2.15.1 版本中的修复所解决,且在所有包含 2.15.1 修复版本预期的

AI Predicted 9.8 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103646

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ultimate Multisite < 2.17.0 - Unauthenticated Authentication Bypass via 'email_address' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, including a Network Super Admin, whose email address they know. This bypass is not addressed by the 2.15.1 fix for CVE-2026-75957 and remains exploitable in all versions up to and including 2.16.1, the releases that fix was expected to cover. Exploitation requires a checkout form configured without a password field (auto-generated password) and a target account that has no existing customer record in the Ultimate Multisite WordPress plugin before 2.17.0.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Ultimate Multisite 0 ~ 2.17.0 -

II. Public POCs for CVE-2026-103646

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103646

请登录查看更多情报信息。

Other References for CVE-2026-103646 (1)

Same Patch Batch · Unknown · 2026-10-08 · 24 CVEs total

CVE-2026-93509 6.5 MEDIUM Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Wallet Balance Manipulation via
CVE-2026-103517 5.3 MEDIUM Airwallex Online Payments Gateway < 1.36.0 - Unauthenticated Payment Bypass via Forged Web
CVE-2026-104671 5.3 MEDIUM TutorStarter < 4.0.4 - Unauthenticated User Registration Bypass via AJAX
CVE-2026-105190 5.3 MEDIUM Easy Digital Downloads < 3.7.1 - Unauthenticated Account Creation with Registration Disabl
CVE-2026-103309 GPTranslate < 2.34.14 - Unauthenticated Stored XSS via REST API Translation Storage
CVE-2026-104646 Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Stored XSS via Gallery Shortc
CVE-2026-104645 Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Arbitrary Gallery Cloning, Im
CVE-2026-103692 Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Func
CVE-2026-105195 Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure
CVE-2026-105197 LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR
CVE-2026-105198 LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR
CVE-2026-105194 Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Dow
CVE-2026-105196 LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API
CVE-2026-105193 Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification
CVE-2026-86826 BackWPup < 5.7.7 - Unauthenticated Sensitive Data Disclosure via Restore Working Directory
CVE-2026-86827 BackWPup 3.3 - 5.7.6 - Unauthenticated Backup Job Execution via wp-cron.php
CVE-2026-86828 BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip Fallback
CVE-2026-105260 Database Addon For WPForms < 1.1.1 - Arbitrary Form Entry Deletion via CSRF
CVE-2026-94246 Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Forged Wallet Withdrawal Reques
CVE-2026-94244 Wallet System for WooCommerce < 2.8.0 - Subscriber+ Store-Wide Wallet Transaction Disclosu

Showing top 20 of 24 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-103646

No comments yet


Leave a comment