Get real-time updates on Telegram
Verified
CVE-2026-103646: Ultimate Multisite 0 to before 2.17.0
Affected technology
Ultimate Multisite · 0 to before 2.17.0
Vendor not specified by the source
Description’s affected range: before 2.17.0 does not require authentication before a logged-out checkout is linked to
Component: Not specified by the source
What an attacker can do
So an unauthenticated attacker can log in as any existing user, including a Network Super Admin, whose email address they know.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 08:49:39.219831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-103646.html