{
 "id": "WPSEC-2026-0664",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0664/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0664/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0664/index.md",
 "title": "WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via Social Login 'uuid' Parameter",
 "description": "The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.27. The social login callback stores a user-supplied value in a shared session entry named after the 'uuid' parameter without restricting that name, and the plugin later trusts shared entries of that kind as verified provider data. This makes it possible for unauthenticated attackers to log in as a user who has linked a Weibo or WeChat account, provided the attacker knows that user's social account identifier. Exploitation requires Weibo or WeChat login to be configured.",
 "plugin": {
  "slug": "wpcom-member",
  "name": "WPCOM Member",
  "full_name": "WPCOM Member",
  "wordpress_org": "https://wordpress.org/plugins/wpcom-member/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wpcom-member/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wpcom-member"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-287"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 8.1,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.8.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.8.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.8.0",
 "remediation": "Update to 1.8.0 or later.",
 "fix_released": "2026-10-07T15:10:27+00:00",
 "published": "2026-10-08T15:50:18+00:00",
 "updated": "2026-10-07T18:51:20.633349+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0664/",
  "https://plugins.svn.wordpress.org/wpcom-member/tags/1.8.0/",
  "https://wordpress.org/plugins/wpcom-member/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wpcom-member",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}