← Back to CVE search

CVE-2026-8457

WooCommerce - Social Login

Description

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin-s Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple-s public keys or validating the issuer, audience, or expiry claims, combined with the security nonce required to invoke the login flow being publicly exposed to unauthenticated users via a localized JavaScript object on the login page. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying a forged id_token whose payload contains the target user-s email address, as that email is used without any role exclusion to resolve a WordPress account and immediately issue an authenticated session for it.

CVSS 9.8EPSS 0.4%Risk 1.02
View source
Published
2026-08-02 00:16:23
Affected versions
<= 2.8.7
Type
Web application
Last modified
2026-08-03 19:16:53
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H