PatchSiren

whyun CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL whyun CVE published 2026-10-10

CVE-2026-104803

The WPCOM Member plugin for WordPress has a critical vulnerability allowing unauthenticated authentication bypass via 'uuid' and 'code' parameters on social-login callback, affecting versions up to 1.7.27. This vulnerability exists due to a lack of nonce validation, OAuth state verification, and per-visitor namespace isolation in the session store. Successful exploitation of this vulnerability could allow [truncated]