# WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via Social Login 'uuid' Parameter

- **ID:** WPSEC-2026-0664
- **Plugin:** WPCOM Member (`wpcom-member`), https://wordpress.org/plugins/wpcom-member/
- **Affected versions:** all versions before 1.8.0
- **Fixed in:** 1.8.0 (Update to 1.8.0 or later.)
- **Severity:** High 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-287
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wpcom-member
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0664/

## Description

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.27. The social login callback stores a user-supplied value in a shared session entry named after the 'uuid' parameter without restricting that name, and the plugin later trusts shared entries of that kind as verified provider data. This makes it possible for unauthenticated attackers to log in as a user who has linked a Weibo or WeChat account, provided the attacker knows that user's social account identifier. Exploitation requires Weibo or WeChat login to be configured.

## References

- https://wpsec.com/vuln/WPSEC-2026-0664/
- https://plugins.svn.wordpress.org/wpcom-member/tags/1.8.0/
- https://wordpress.org/plugins/wpcom-member/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0664/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
