Skip to content
firewallpulse
Bits, bytes and breaking security news
Vulnerabilities

WPCOM Member Authentication Bypass Allows Unauthorised Admin Access via Social Login Flaws

A critical authentication bypass in the WPCOM Member plugin for WordPress allows attackers to hijack admin accounts by forging social login sessions without valid credentials.

WPCOM Member Authentication Bypass Allows Unauthorised Admin Access via Social Login Flaws
Illustration: Firewall Pulse

Key points

  • The vulnerability affects all WPCOM Member versions up to and including 1.7.27.
  • Attackers can bypass authentication by exploiting missing nonce and OAuth state checks.
  • Successful exploitation requires knowledge of a victim’s bound social provider identifier.

The WPCOM Member plugin for WordPress contains a critical authentication bypass vulnerability. According to the National Vulnerability Database, this flaw allows unauthenticated attackers to log in as any user, including administrators, by manipulating social login parameters. The issue stems from inadequate validation in the plugin’s callback handler.

Root cause

The vulnerability exists within the `login` function’s social-login flow. The plugin fails to perform nonce validation, OAuth state verification, or per-visitor namespace isolation in the session store. This lack of security controls allows attackers to inject forged data into the global session namespace. The flaw is rated CVSS 9.8 Critical by the NVD.

Attack path

An attacker issues a crafted GET request using the `uuid` and `code` parameters. This request writes an attacker-controlled entry into the global session namespace by bypassing the per-visitor prefix with an underscore. A second GET request triggers the `weapp_new_user()` function, which reads the forged entry. This resolves the attacker-supplied `openid` to a bound WordPress account, establishing an authenticated session.

Affected versions

  • WPCOM Member version 1.7.27
  • All versions of WPCOM Member prior to 1.7.27
  • The vulnerability is present in any installation where a social provider is configured

Mitigation

  • Verify if the WPCOM Member plugin is installed and active on your WordPress site.
  • Check if any social login providers are configured, as this activates the vulnerable handler.
  • Monitor server logs for unusual GET requests targeting the social-login callback handler.
  • Ensure that user account social identifiers are not publicly discoverable or easily enumerable.

What to do and how to stay safe: WPCOM Member

  • Audit your WordPress installations to identify if the WPCOM Member plugin is installed and at which version.
  • Review access logs for suspicious activity related to social login endpoints, particularly unusual GET requests.
  • Restrict access to administrative interfaces using IP whitelisting or additional authentication layers.
  • Wait for the vendor to release a patched version before updating, and monitor security advisories for confirmation.

General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is the CVSS score for CVE-2026-104803?

The National Vulnerability Database rates CVE-2026-104803 as CVSS 9.8 Critical.

Which plugin versions are affected by this authentication bypass?

All versions of the WPCOM Member plugin up to and including version 1.7.27 are affected.

What does an attacker need to successfully exploit this vulnerability?

The attacker needs a target site with a configured social provider and knowledge of a victim’s bound openid or unionid.

Sources

  1. CVE Program
  2. NVD
WPCOM MemberWordPressCVE-2026-104803Authentication BypassNVD

Related stories