CRITICAL 9.8 CVE-2026-77002 Published 22 Aug 2026

WordPress SmilePass Selfie Login Auth Bypass

Worried this affects one of your servers?

The SmilePass Selfie Login WordPress plugin, up to version 1.0.2, has a critical vulnerability. It does not verify user identities server-side, allowing any unauthenticated user to log in as any registered account, including administrators.

Impact: This could lead to unauthorized access and potential data breaches.

Reference: CVE-2026-77002 on NVD

← Back to Security News