Description
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.
Published: 2026-08-22
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Social Media Login plugin, up to and including version 1.0.6, fails to confirm that an authentication session with the external identity provider (Twitter) was actually completed, permitting an unauthenticated attacker to log in as any existing WordPress user by simply providing that user’s email address. An attacker who succeeds in this process obtains the credentials and privileges of the targeted account, potentially including super‑user rights. This flaw is an example of improper authentication (CWE‑287).

Affected Systems

WordPress sites that have the WP Social Media Login plugin installed with a version of 1.0.6 or older are affected. No additional vendor or product variants are listed, and no specific sub‑versions beyond the stated maximum are mentioned.

Risk and Exploitability

The exploit requires no prior authentication and can be performed remotely through the normal social‑login interface, merely by submitting an arbitrary email address. Because the flaw allows direct account takeover, it is considered highly impactful. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, but the risk remains significant due to the simplicity of the attack and the severity of the impact.

Generated by OpenCVE AI on August 22, 2026 at 07:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Social Media Login to the latest available version that includes the authentication verification fix
  • If an update is not immediately possible, disable the social‑login feature until a patched version is installed
  • Review and restrict the use of administrator email addresses so that attackers cannot target privileged accounts

Generated by OpenCVE AI on August 22, 2026 at 07:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.
Title WP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter Login Flow
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-22T06:00:17.601Z

Reserved: 2026-08-20T07:24:00.357Z

Link: CVE-2026-77000

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T06:16:17.150

Modified: 2026-08-22T06:16:17.150

Link: CVE-2026-77000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T08:00:13Z

Weaknesses

No weakness.