CRITICAL 9.8 CVE-2026-104803 Published 10 Oct 2026

WPCOM Member Plugin Authentication Bypass Vulnerability

Worried this affects your website?

The WPCOM Member plugin for WordPress is vulnerable to an Authentication Bypass in all versions up to and including 1.7.27. The flaw is in the social-login callback handler registered on the init hook, via the uuid and code parameters.

The login function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation in the session store. An unauthenticated attacker can send a crafted GET request to write an attacker-controlled entry into the global session namespace, then send a second GET request that triggers weapp_new_user() to read the forged entry and resolve the attacker-supplied openid to a bound WordPress account before wp_set_auth_cookie() establishes a fully authenticated session.

  • Affects all versions up to and including 1.7.27.
  • Requires at least one social provider configured on the target site.
  • Attacker must know or enumerate the victim account's bound openid or unionid.
  • Impact: unauthenticated attackers can log in as any WordPress user, including administrators.

Reference: CVE-2026-104803 on NVD

← Back to Security News