Description
The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability exists because the `login` function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation in the session store, allowing an unauthenticated attacker to issue a crafted GET request that writes an attacker-named, attacker-valued entry into the global session namespace (bypassing the per-visitor prefix by prepending an underscore), then issue a second GET request triggering `weapp_new_user()` to read that forged entry and resolve the attacker-supplied `openid` value to a bound WordPress account before `wp_set_auth_cookie()` establishes a fully authenticated session. This makes it possible for unauthenticated attackers to log in as any WordPress user — including administrators — whose bound social provider identifier (openid/unionid) is known or discoverable. Successful exploitation requires that the target site has at least one social provider configured (which activates the vulnerable handler) and that the attacker knows or can enumerate the victim account's bound openid or unionid.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Authentication Bypass allowing an attacker to impersonate any WordPress user.
Action: Patch Now
AI Analysis

Impact

The WPCOM Member plugin implements a social‑login callback that does not validate nonces, OAuth state, or isolate per‑visitor session data. By sending a crafted GET request containing a uuid and code parameter, an unauthenticated attacker can inject a session entry that causes the system to resolve an attacker‑supplied openid to a legitimate WordPress account and establish a fully authenticated session. The result is that the attacker can log in as any user, including administrators, when the victim’s social provider identifier is known or can be discovered.

Affected Systems

This flaw affects the WordPress WPCOM Member plugin provided by whyun, in all releases up to and including version 1.7.27.

Risk and Exploitability

The vulnerability scores a CVSS of 9.8, indicating critical severity, and the EPSS score is not available. It is not listed in the CISA KEV catalog. Exploitation requires the target WordPress site to have at least one active social provider configured and for the attacker to know or enumerate the victim’s openid or unionid. The likely attack vector is a crafted HTTP GET request targeting the social‑login callback endpoint, which an unauthenticated party can trigger without any credentials.

Generated by OpenCVE AI on October 10, 2026 at 09:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WPCOM Member plugin to version 1.7.28 or later, which removes the flawed authentication flow.
  • If an immediate upgrade is not feasible, disable social‑login functionality or remove the vulnerable callback handler until a patch can be applied.
  • Clear the WordPress session store to remove any forged session entries that could have been created by an attacker.
  • Implement monitoring for unexpected authentication events and enforce strict input validation on social‑login parameters as a general security best practice.

Generated by OpenCVE AI on October 10, 2026 at 09:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability exists because the `login` function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation in the session store, allowing an unauthenticated attacker to issue a crafted GET request that writes an attacker-named, attacker-valued entry into the global session namespace (bypassing the per-visitor prefix by prepending an underscore), then issue a second GET request triggering `weapp_new_user()` to read that forged entry and resolve the attacker-supplied `openid` value to a bound WordPress account before `wp_set_auth_cookie()` establishes a fully authenticated session. This makes it possible for unauthenticated attackers to log in as any WordPress user — including administrators — whose bound social provider identifier (openid/unionid) is known or discoverable. Successful exploitation requires that the target site has at least one social provider configured (which activates the vulnerable handler) and that the attacker knows or can enumerate the victim account's bound openid or unionid.
Title WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Parameters on Social-Login Callback
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:44.669Z

Reserved: 2026-10-02T13:20:56.523Z

Link: CVE-2026-104803

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:04.210

Modified: 2026-10-10T08:17:04.210

Link: CVE-2026-104803

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses