A popular WordPress plugin used to add Apple social login options to WooCommerce stores has a serious security vulnerability that impacts all versions up to and including 2.8.7. The flaw exists because the plugin fails to properly validate Apple login requests, and a security safeguard meant to protect the login process is publicly visible on your site's login page. This makes it possible for people who are not logged into your site to access any existing user account on your WordPress site, including administrator accounts, by submitting a forged fake Apple login request tied to the target user's email address.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-8457