CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-103646: Ultimate Multisite 0 to before 2.17.0

Affected technology

Ultimate Multisite · 0 to before 2.17.0
Vendor not specified by the source

Description’s affected range: before 2.17.0 does not require authentication before a logged-out checkout is linked to

Component: Not specified by the source

What an attacker can do

So an unauthenticated attacker can log in as any existing user, including a Network Super Admin, whose email address they know.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-103646.html