A important vulnerability within the WooCommerce Social Login WordPress plugin permits unauthenticated attackers to log in as any current consumer, together with an administrator. The authentication bypass vulnerability is rated 9.8 out of 10 and impacts all variations as much as and together with 2.8.7.
WooCommerce Social Login Plugin
The WooCommerce Social Login plugin permits frictionless one-click login for ecommerce retailer prospects and permits quick checkout utilizing accounts from companies equivalent to Fb, Google, Amazon, PayPal, and Apple.
Unauthenticated Authentication Bypass
This vulnerability is particularly regarding as a result of attackers don’t want to accumulate any consumer permission function to take advantage of it.
The vulnerability impacts the plugin’s Apple login handler, which processes the data acquired when somebody indicators in with an Apple account.
Apple gives an identification token containing details about the particular person making an attempt to log in. The token is protected by a digital signature that ought to be checked in opposition to Apple’s public keys to substantiate that it’s genuine. That is the place the plugin fails, enabling attackers to offer the e-mail deal with of an current consumer and acquire entry to that account.
In response to Wordfence:
“This makes it attainable for unauthenticated attackers to log in as any current WordPress consumer — together with directors — by supplying a solid id_token whose payload comprises the goal consumer’s e-mail deal with, as that e-mail is used with none function exclusion to resolve a WordPress account and instantly concern an authenticated session for it.”
As a result of administrator accounts are usually not excluded from this exploit, a profitable assault might present administrative entry to the WooCommerce web site that makes use of this plugin.
The vulnerability was assigned the Frequent Vulnerabilities and Exposures identifier CVE-2026-8457 and publicly disclosed on August 1, 2026.
Wordfence recommends that customers of variations as much as and together with 2.8.7 ought to replace to model 2.8.8 or larger model.
Featured Picture by Shutterstock/file404
#WooCommerce #Social #Login #WordPress #Plugin #Permits #Full #Web site #Takeover

