CRITICAL
whyun
CVE published 2026-10-10
CVE-2026-104803
The WPCOM Member plugin for WordPress has a critical vulnerability allowing unauthenticated authentication bypass via 'uuid' and 'code' parameters on social-login callback, affecting versions up to 1.7.27. This vulnerability exists due to a lack of nonce validation, OAuth state verification, and per-visitor namespace isolation in the session store. Successful exploitation of this vulnerability could allow [truncated]