A security vulnerability has been discovered in the WooCommerce Social Login plugin for WordPress, impacting all versions up to and including 2.8.7. The flaw affects the plugin's Apple sign-in functionality. It fails to properly confirm that login tokens sent from Apple are valid, and a private security check meant to protect the login flow is visible in public code on your site's login page that any visitor can access. This allows unauthenticated attackers to create fake login tokens linked to the email address of any existing user on your WordPress site. If this vulnerability is exploited, an attacker can use the fake token to log in as that user, including site administrators. This would grant the attacker full control over your WordPress site and any connected WooCommerce store, letting them alter site content, access private customer information, or make unauthorized changes to your store's operations.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-8457