{"id":"CVE-2026-80099","title":"Several Newfold plugins are vulnerable to Authentication Bypass","summary":"Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` f…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-287"],"vendor":"Newfold","product":"WP Plugin Web","affected":["wp_plugin_web <= 2.3.5","wp_plugin_crazy_domains <= 2.5.2","wp_module_data <= 2.9.7","wp_plugin_hostgator <= 3.2.0","wp_plugin_bluehost <= 4.19.0"],"published":"2026-09-09","updated":"2026-09-09","sourceUpdated":"2026-09-09T17:17:45.587","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80099","references":[{"url":"https://github.com/newfold-labs/wp-module-data/commit/9d913fd8fa12796c4d9c09081e4aeccfa5cb1301","label":"security@wordfence.com"},{"url":"https://github.com/newfold-labs/wp-plugin-bluehost/compare/4.19.0...4.19.1","label":"security@wordfence.com"},{"url":"https://github.com/newfold-labs/wp-plugin-crazy-domains/compare/2.5.2...2.5.3","label":"security@wordfence.com"},{"url":"https://github.com/newfold-labs/wp-plugin-hostgator/compare/3.2.0...3.2.1","label":"security@wordfence.com"},{"url":"https://github.com/newfold-labs/wp-plugin-web/compare/2.3.5...2.3.6","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-module-data/trunk/includes/Data.php#L191","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-module-data/trunk/includes/Data.php#L201","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-module-data/trunk/includes/Data.php#L222","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-module-data/trunk/includes/Data.php#L69","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-module-data/trunk/includes/HiiveConnection.php#L406","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3ee369c0-0d7c-4142-b3ba-a518288647ba?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org","exploit-available"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-09T15:41:26.162294Z"},"ingestedAt":"2026-09-10T09:55:16.808Z","epss":0.00508,"epssPercentile":0.42257,"exploits":{"github":1,"githubRepos":["https://github.com/Wayang1337/CVE-2026-80099"],"checkedAt":"2026-09-21T15:30:47.320Z"},"exploitAvailable":true,"slug":"CVE-2026-80099","body":"## Overview\n\nSeveral Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request — performs an HMAC-style Bearer token comparison that degenerates when `HiiveConnection::get_auth_token()` returns `false`: PHP coerces `strrev(false)` to `strrev('')`, collapsing the secret salt to the publicly known constant `hash('sha256', '') = e3b0c44...`, while all remaining hash inputs (HTTP method, request URL, raw request body, and the `X-Timestamp` header) remain fully attacker-controlled. This makes it possible for unauthenticated attackers to compute a valid Bearer token entirely offline, pass the token equality check, and have `wp_set_current_user()` invoked against the first administrator returned by `get_users(['role' => 'administrator'])`, granting full administrator-level access and enabling arbitrary REST API operations such as creating new administrator accounts and achieving complete site takeover. Vulnerable versions are WP Plugin Crazy Domains (<= 2.5.2), WP Plugin Web (<= 2.3.4), WP Plugin Hostgator (<= 3.1.0), WP Plugin Bluehost (<= 4.17.1). The affected module is vulnerable in versions up to, and including, 2.9.4.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}