## Overview
Several Newfold plugins are vulnerable to an authentication bypass flaw, identified as CVE-2026-80099. This vulnerability affects the Crazy Domains, Web, Hostgator, and Bluehost plugins. It allows unauthenticated attackers to gain administrator-level access.
## Technical Details
The vulnerability arises from the wp-module-data module bundled with these plugins. The `authenticate()` method, which is registered on the `rest_authentication_errors` filter, is evaluated for every unauthenticated REST API request. When `HiiveConnection::get_auth_token()` returns `false`, PHP coerces `strrev(false)` to `strrev('')`. This leads to a collapse of the secret salt to a known constant, allowing attackers to compute a valid Bearer token offline.
The inputs for the HMAC-style Bearer token comparison remain under attacker control, including the HTTP method, request URL, raw request body, and the `X-Timestamp` header. This flaw permits attackers to pass the token equality check and invoke `wp_set_current_user()` against the first administrator returned by `get_users(['role' => 'administrator'])`.
## Impact
Successful exploitation of this vulnerability grants full administrator-level access to the attacker. This access enables arbitrary REST API operations, including the creation of new administrator accounts and complete site takeover. The affected plugins are:
- WP Plugin Crazy Domains (<= 2.5.2)
- WP Plugin Web (<= 2.3.4)
- WP Plugin Hostgator (<= 3.1.0)
- WP Plugin Bluehost (<= 4.17.1)
The vulnerable module is affected in versions up to and including 2.9.4.
## Mitigation
Defenders should update all affected Newfold plugins to the latest versions immediately. Regularly review and monitor plugin usage and access to REST APIs to mitigate potential exploitation.
CSURFACE Threat Sensor