# WPCOM Member <= 1.7.27 - Cross-Site Request Forgery to Account Takeover via Social Login Binding

- **ID:** WPSEC-2026-0663
- **Plugin:** WPCOM Member (`wpcom-member`), https://wordpress.org/plugins/wpcom-member/
- **Affected versions:** all versions before 1.8.0
- **Fixed in:** 1.8.0 (Update to 1.8.0 or later.)
- **Severity:** High 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-352
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wpcom-member
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0663/

## Description

The WPCOM Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.27. The social login callback does not validate the OAuth state parameter and accepts the account-binding mode from a URL parameter. This makes it possible for unauthenticated attackers to bind a social account they control to a logged-in user's account and then log in as that user, granted they can trick the user into performing an action such as clicking a link. Exploitation requires social login to be enabled with at least one provider configured.

## References

- https://wpsec.com/vuln/WPSEC-2026-0663/
- https://plugins.svn.wordpress.org/wpcom-member/tags/1.8.0/
- https://wordpress.org/plugins/wpcom-member/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0663/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
