If your WordPress site uses the WooCommerce Social Login plugin in version 2.8.7 or older, the plugin has a critical security flaw in its Apple login feature. The plugin fails to properly verify that Apple login requests are legitimate, and a security protection meant to limit access to the login flow is publicly exposed to all visitors via visible code on your site's login page.
This flaw lets unauthenticated attackers bypass all standard login security for your site. They can create a forged fake Apple login request that tricks the plugin into logging them in as any existing user on your WordPress site, including full administrator accounts. If an attacker gains administrator access, they can take complete control of your site, access customer data, modify your store settings, or carry out other harmful actions.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-8457