๐Ÿ” CVE Alert

CVE-2026-104803

CRITICAL 9.8

WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Parameters on Social-Login Callback

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability exists because the `login` function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation in the session store, allowing an unauthenticated attacker to issue a crafted GET request that writes an attacker-named, attacker-valued entry into the global session namespace (bypassing the per-visitor prefix by prepending an underscore), then issue a second GET request triggering `weapp_new_user()` to read that forged entry and resolve the attacker-supplied `openid` value to a bound WordPress account before `wp_set_auth_cookie()` establishes a fully authenticated session. This makes it possible for unauthenticated attackers to log in as any WordPress user โ€” including administrators โ€” whose bound social provider identifier (openid/unionid) is known or discoverable. Successful exploitation requires that the target site has at least one social provider configured (which activates the vulnerable handler) and that the attacker knows or can enumerate the victim account's bound openid or unionid.

CWE CWE-287
Vendor whyun
Product wpcom member
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for whyun wpcom member

Be the first to know when new critical vulnerabilities affecting whyun wpcom member are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

whyun / WPCOM Member
0 โ‰ค 1.7.27

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/3dee7f76-bd66-4e54-8ef6-bbf581ebcc11?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/social-login.php#L1235 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/social-login.php#L91 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/social-login.php#L674 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/class-sesstion.php#L13 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wpcom-member/trunk/includes/social-login.php

Credits

Mohamed Khater