Impact
The WPCOM Member plugin implements a social‑login callback that does not validate nonces, OAuth state, or isolate per‑visitor session data. By sending a crafted GET request containing a uuid and code parameter, an unauthenticated attacker can inject a session entry that causes the system to resolve an attacker‑supplied openid to a legitimate WordPress account and establish a fully authenticated session. The result is that the attacker can log in as any user, including administrators, when the victim’s social provider identifier is known or can be discovered.
Affected Systems
This flaw affects the WordPress WPCOM Member plugin provided by whyun, in all releases up to and including version 1.7.27.
Risk and Exploitability
The vulnerability scores a CVSS of 9.8, indicating critical severity, and the EPSS score is not available. It is not listed in the CISA KEV catalog. Exploitation requires the target WordPress site to have at least one active social provider configured and for the attacker to know or enumerate the victim’s openid or unionid. The likely attack vector is a crafted HTTP GET request targeting the social‑login callback endpoint, which an unauthenticated party can trigger without any credentials.
OpenCVE Enrichment