Vulnerabilities / WPCOM Member / WPSEC-2026-0664

WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via Social Login 'uuid' Parameter

High 8.1 CWE-287Fixed in 1.8.0
ID
WPSEC-2026-0664
Plugin
WPCOM Member (wpcom-member)
Affected
all versions before 1.8.0
Remediation
Update to 1.8.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-287
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
WPCOM Member on WPSec AttackSurface
Fix released
Published

Description

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.27. The social login callback stores a user-supplied value in a shared session entry named after the 'uuid' parameter without restricting that name, and the plugin later trusts shared entries of that kind as verified provider data. This makes it possible for unauthenticated attackers to log in as a user who has linked a Weibo or WeChat account, provided the attacker knows that user's social account identifier. Exploitation requires Weibo or WeChat login to be configured.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0