CVE-2026-80099

Summary

Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the authenticate() method — registered on the rest_authentication_errors filter and therefore evaluated for every unauthenticated REST API request — performs an HMAC-style Bearer token comparison that degenerates when HiiveConnection::get_auth_token() returns false: PHP coerces strrev(false) to strrev(&#39;&#39;), collapsing the secret salt to the publicly known constant hash(&#39;sha256&#39;, &#39;&#39;) = e3b0c44..., while all remaining hash inputs (HTTP method, request URL, raw request body, and the X-Timestamp header) remain fully attacker-controlled. This makes it possible for unauthenticated attackers to compute a valid Bearer token entirely offline, pass the token equality check, and have wp_set_current_user() invoked against the first administrator returned by get_users([&#39;role&#39; =&gt; &#39;administrator&#39;]), granting full administrator-level access and enabling arbitrary REST API operations such as creating new administrator accounts and achieving complete site takeover. Vulnerable versions are WP Plugin Crazy Domains (<= 2.5.2), WP Plugin Web (<= 2.3.4), WP Plugin Hostgator (<= 3.1.0), WP Plugin Bluehost (<= 4.17.1). The affected module is vulnerable in versions up to, and including, 2.9.4.

Affected Software

VendorProductVersion RangeStatus
NewfoldWP Plugin Web0 <= 2.3.5affected
NewfoldWP Plugin Crazy Domains0 <= 2.5.2affected
NewfoldWP Module Data0 <= 2.9.7affected
NewfoldWP Plugin Hostgator0 <= 3.2.0affected
NewfoldWP Plugin Bluehost0 <= 4.19.0affected

Weaknesses

  • CWE-287: CWE-287 Improper Authentication

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References