CVE-2026-103646

CVE-2026-103646 published: The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalize...

View full NVD advisory → ← Back to CVE watch