CVE-2026-8457 (matched: wordpress)

  • Sunday, 2nd August, 2026
  • 04:04am

A security vulnerability tracked as CVE-2026-8457 affects the WooCommerce Social Login plugin for WordPress, impacting all versions up to and including 2.8.7. The flaw exists in how the plugin processes Apple logins: it does not validate that login tokens from Apple are legitimate, and a required security check for starting the login flow is publicly visible to anyone who visits your site’s WordPress login page. This gap allows unauthenticated third parties to create fake login credentials to access any existing user account on your site, including administrator accounts. If an attacker knows the email address linked to a user on your site, they can exploit this flaw to log in as that user and gain full control over your WordPress dashboard and website content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-8457

« Back