CVE-2026-80099 carries a CVSS 3.1 base score of 8.8 against a shared module used across several Newfold-branded WordPress plugins. NVD classifies it as CWE-287 (Improper Authentication) and states the affected component is wp-module-data, a module bundled by WP Plugin Crazy Domains (up to 2.5.2), WP Plugin Web (up to 2.3.4), WP Plugin Hostgator (up to 3.1.0), and WP Plugin Bluehost (up to 4.17.1) — versions of the module itself up to and including 2.9.4 are affected. VulnCheck’s KEV feed reports the CVE as exploited, dated September 9, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-80099 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description states the flaw is in wp-module-data’s authentication handler, which runs on every unauthenticated REST API request via the rest_authentication_errors filter. NVD describes the handler’s Bearer-token check as degrading to a predictable, publicly known value under a specific edge condition involving how an internal helper method reports its own token state — leaving the check unable to distinguish a legitimate caller from an attacker in that condition. NVD states a successful bypass results in wp_set_current_user() being invoked against the site’s first Administrator account, granting full administrative REST API access.
We are reporting NVD’s description of the flawed component and its impact, not the specific value-computation steps an attacker would need to reproduce the bypass. Notably, NVD’s own CVSS vector marks this PR:L (low privileges required), while its description frames the resulting access as available to “unauthenticated attackers” — a tension in NVD’s own record between the formal vector and the prose description that we are surfacing rather than resolving in either direction.
Evidence and confidence
- Medium confidence — the CVSS 8.8 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), the CWE-287 classification, the affected products and versions, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by Newfold’s own linked GitHub commit and Wordfence’s threat intelligence entry. The exploitation report traces to VulnCheck KEV alone. - Moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00508, a 42.1th percentile score as of our ingestion.
- Unresolved internal tension — NVD’s CVSS vector states
PR:L(low privileges required) while NVD’s own description characterizes the attack as achievable by “unauthenticated attackers.” We report both as NVD states them rather than picking one.
Why this matters
Newfold operates several of the WordPress hosting industry’s largest bundled-plugin brands — Bluehost, Hostgator, Crazy Domains, and Web.com among them — meaning a shared authentication module vulnerability like this one can affect a large population of hosted WordPress sites simultaneously, regardless of which specific branded plugin a site owner installed. A full administrative REST API compromise from this class of flaw enables complete site takeover, including new administrator account creation and arbitrary content or configuration changes via the REST API.
Because the exploitation report is VulnCheck-only and not yet corroborated by CISA, and because NVD’s own record carries an unresolved discrepancy between its formal privilege requirement and its prose description, site operators should treat this as a credible, high-severity flaw warranting prompt patching rather than waiting for further confirmation.
Frequently Asked Questions
What is CVE-2026-80099?
A CVSS 8.8 authentication bypass vulnerability (CWE-287) in Newfold’s shared wp-module-data module, bundled across the WP Plugin Crazy Domains, WP Plugin Web, WP Plugin Hostgator, and WP Plugin Bluehost WordPress plugins, allowing an attacker to bypass the REST API’s Bearer-token authentication check and be granted administrator-level access.
Is CVE-2026-80099 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 9, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Does an attacker need an account to exploit this?
NVD’s own record is inconsistent on this point: the CVSS vector specifies low privileges required (PR:L), while NVD’s description characterizes the attack as achievable by unauthenticated attackers. We report this discrepancy rather than resolving it.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which versions fix this?
Per NVD: WP Plugin Crazy Domains 2.5.3+, WP Plugin Web 2.3.6+, WP Plugin Hostgator 3.2.1+, WP Plugin Bluehost 4.19.1+, and wp-module-data above 2.9.4.
Severity, vector, weakness classification, affected versions, and mechanism sourced from the National Vulnerability Database record for CVE-2026-80099, corroborated by Newfold’s own fix commit and Wordfence’s threat intelligence entry. Exploitation status and the September 9, 2026 catalog date reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.