Vulnerabilities / WPCOM Member / WPSEC-2026-0663

WPCOM Member <= 1.7.27 - Cross-Site Request Forgery to Account Takeover via Social Login Binding

High 7.5 CWE-352Fixed in 1.8.0
ID
WPSEC-2026-0663
Plugin
WPCOM Member (wpcom-member)
Affected
all versions before 1.8.0
Remediation
Update to 1.8.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness
CWE-352
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
WPCOM Member on WPSec AttackSurface
Fix released
Published

Description

The WPCOM Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.27. The social login callback does not validate the OAuth state parameter and accepts the account-binding mode from a URL parameter. This makes it possible for unauthenticated attackers to bind a social account they control to a logged-in user's account and then log in as that user, granted they can trick the user into performing an action such as clicking a link. Exploitation requires social login to be enabled with at least one provider configured.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0