PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104803 whyun CVE debrief

The WPCOM Member plugin for WordPress has a critical vulnerability allowing unauthenticated authentication bypass via 'uuid' and 'code' parameters on social-login callback, affecting versions up to 1.7.27. This vulnerability exists due to a lack of nonce validation, OAuth state verification, and per-visitor namespace isolation in the session store. Successful exploitation of this vulnerability could allow an unauthenticated attacker to log in as any WordPress user, including administrators, whose bound social provider identifier is known or discoverable. This could lead to unauthorized access to sensitive areas of the site and potentially allow for the impersonation of high-privile

Vendor
whyun
Product
WPCOM Member
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

WordPress administrators, defenders, and security teams responsible for maintaining WPCOM Member plugin installations should be concerned about this vulnerability. They should assess their exposure, apply patches or updates, and monitor for suspicious activity related to social-login callback handlers. Additionally, they should verify social provider configurations and consider additional security measures to protect against potential attacks.

Why it matters

CVE-2026-104803 is a critical vulnerability in the WPCOM Member plugin for WordPress, allowing unauthenticated authentication bypass via 'uuid' and 'code' parameters on social-login callback. Defenders should assess exposure, apply patches, and monitor for suspicious activity.

  • Unauthenticated attackers can gain access to sensitive areas of the site
  • Administrators and high-privilege users are at risk of being impersonated
  • Successful exploitation can lead to unauthorized access to sensitive data
  • Defenders need to verify patch deployment and monitor for suspicious activity

Technical summary

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass due to lack of nonce validation, OAuth state verification, and per-visitor namespace isolation in the session store. This allows attackers to forge session entries and gain unauthorized access. The vulnerability affects versions up to 1.7.27 and can be exploited by unauthenticated attackers. Successful exploitation requires that the target site has at least one social provider configured. Defenders should assess exposure, apply patches, and monitor for suspicious activity.

Defensive priority

High priority for WordPress administrators and defenders to assess exposure and apply patches

Recommended defensive actions

  • Assess exposure by checking if the WPCOM Member plugin version is 1.7.27 or earlier
  • Apply patches or updates to the WPCOM Member plugin to address the vulnerability
  • Monitor for suspicious activity related to social-login callback handlers
  • Verify social provider configurations and consider additional security measures
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability exists due to lack of nonce validation, OAuth state verification, and per-visitor namespace isolation in the session store, allowing attackers to forge session entries and gain unauthorized access.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104803 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104803

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104803 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104803

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Parameters

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104803.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/social-login.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/class-sesstion.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wpcom-member/trunk/includes/social-login.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.