CRITICAL 9.8 CVE-2026-77000 Published 22 Aug 2026

WordPress WP Social Media Login Plugin Unauthenticated User Login

Worried this affects one of your servers?

The WP Social Media Login WordPress plugin, up to version 1.0.6, has a security flaw that allows unauthenticated attackers to log in as any existing user, including administrators, without completing a social login with the identity provider.

This vulnerability can be exploited by supplying the target user's email address, granting attackers unauthorized access to the victim's account.

Reference: CVE-2026-77000 on NVD

← Back to Security News