PatchSiren

SmilePass CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL SmilePass CVE published 2026-08-22

CVE-2026-77002

The SmilePass Selfie Login WordPress plugin through 1.0.2 is vulnerable to an authentication bypass. This vulnerability allows unauthenticated users to log in as any registered account, including administrators, due to a lack of server-side verification of the identity being authenticated. The CVE record was published on 2026-08-22T06:16:17.510Z and has not been modified since then. Affected WordPress sit [truncated]