NVD CRITICAL: CVE-2026-75957 — The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for Wor...
The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible `wu_ajax_nopriv_wu_validate_form` AJAX handler accepting a freely obtainable checkout nonce, and the `check
CVE-2026-75957