Impact
The SmilePass Selfie Login WordPress plugin, in versions up to 1.0.2, does not perform any server‑side identity verification during the authentication process. This flaw allows an attacker to submit any user identifier and gain access as that user without providing a valid credential, effectively bypassing authentication and potentially granting full administrative privileges.
Affected Systems
The vulnerability affects the SmilePass Selfie Login plugin for WordPress, version 1.0.2 and earlier. Site administrators using this plugin have no vendor‑provided name listed, so the product is commonly described simply as "SmilePass Selfie Login".
Risk and Exploitability
The CVSS score of 9.8 reflects critical severity, while the EPSS score of <1% indicates a low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending a request to the plugin’s authentication endpoint with the desired username, bypassing all server‑side checks and gaining access as any registered user, including administrators.
OpenCVE Enrichment