WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via Social Login 'uuid' Parameter
- ID
- WPSEC-2026-0664
- Plugin
- WPCOM Member (wpcom-member)
- Affected
- all versions before 1.8.0
- Remediation
- Update to 1.8.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-287
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- WPCOM Member on WPSec AttackSurface
- Fix released
- Published
Description
The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.27. The social login callback stores a user-supplied value in a shared session entry named after the 'uuid' parameter without restricting that name, and the plugin later trusts shared entries of that kind as verified provider data. This makes it possible for unauthenticated attackers to log in as a user who has linked a Weibo or WeChat account, provided the attacker knows that user's social account identifier. Exploitation requires Weibo or WeChat login to be configured.
References
- https://wpsec.com/vuln/WPSEC-2026-0664/
- https://plugins.svn.wordpress.org/wpcom-member/tags/1.8.0/
- https://wordpress.org/plugins/wpcom-member/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS