Description
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.
Published: 2026-08-22
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Account Takeover
Action: Patch Immediately
AI Analysis

Impact

The WP Social Media Login plugin, up to and including version 1.0.6, fails to confirm that an authentication session with the external identity provider (Twitter) was actually completed, permitting an unauthenticated attacker to log in as any existing WordPress user by simply providing that user’s email address. An attacker who succeeds in this process obtains the credentials and privileges of the targeted account, potentially including super‑user rights. This flaw is an example of improper authentication (CWE‑287).

Affected Systems

WordPress sites that have the WP Social Media Login plugin installed with a version of 1.0.6 or older are affected. No additional vendor or product variants are listed, and no specific sub‑versions beyond the stated maximum are mentioned.

Risk and Exploitability

The exploit requires no prior authentication and can be performed remotely through the normal social‑login interface, merely by submitting an arbitrary email address. Because the flaw allows direct account takeover, it is considered highly impactful. The CVSS score of 9.8 indicates extreme severity, while the EPSS score of <1% shows a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the simplicity of the attack and the magnitude of the potential impact keeps the risk significant.

Generated by OpenCVE AI on August 23, 2026 at 17:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Social Media Login to the latest available version that includes the authentication verification fix
  • If an update is not immediately possible, disable the social‑login feature until a patched version is installed
  • Review and restrict the use of administrator email addresses so that attackers cannot target privileged accounts

Generated by OpenCVE AI on August 23, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 23 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.
Title WP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter Login Flow
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-23T15:38:49.918Z

Reserved: 2026-08-20T07:24:00.357Z

Link: CVE-2026-77000

cve-icon Vulnrichment

Updated: 2026-08-23T15:24:32.762Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T06:16:17.150

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-77000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-23T18:00:03Z

Weaknesses