A security flaw has been found in the WooCommerce Social Login plugin for WordPress, affecting all versions up to and including 2.8.7. The issue is in the plugin's Apple login feature, which does not properly check if login tokens from Apple are legitimate, and also exposes a required security code for the login process to anyone who visits your site's login page, as it is included in public JavaScript code on that page.
This gap lets unauthenticated attackers create fake login tokens to access any existing user account on your WordPress site, including administrator accounts. If an attacker logs in as an admin, they can make unrestricted changes to your site, access sensitive data, or take full control of your WordPress installation.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-8457