PatchSiren cyber security CVE debrief
CVE-2026-104803 whyun CVE debrief
The WPCOM Member plugin for WordPress has a critical vulnerability allowing unauthenticated authentication bypass via 'uuid' and 'code' parameters on social-login callback, affecting versions up to 1.7.27. This vulnerability exists due to a lack of nonce validation, OAuth state verification, and per-visitor namespace isolation in the session store. Successful exploitation of this vulnerability could allow an unauthenticated attacker to log in as any WordPress user, including administrators, whose bound social provider identifier is known or discoverable. This could lead to unauthorized access to sensitive areas of the site and potentially allow for the impersonation of high-privile
- Vendor
- whyun
- Product
- WPCOM Member
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
WordPress administrators, defenders, and security teams responsible for maintaining WPCOM Member plugin installations should be concerned about this vulnerability. They should assess their exposure, apply patches or updates, and monitor for suspicious activity related to social-login callback handlers. Additionally, they should verify social provider configurations and consider additional security measures to protect against potential attacks.
Why it matters
CVE-2026-104803 is a critical vulnerability in the WPCOM Member plugin for WordPress, allowing unauthenticated authentication bypass via 'uuid' and 'code' parameters on social-login callback. Defenders should assess exposure, apply patches, and monitor for suspicious activity.
- Unauthenticated attackers can gain access to sensitive areas of the site
- Administrators and high-privilege users are at risk of being impersonated
- Successful exploitation can lead to unauthorized access to sensitive data
- Defenders need to verify patch deployment and monitor for suspicious activity
Technical summary
The WPCOM Member plugin for WordPress is vulnerable to authentication bypass due to lack of nonce validation, OAuth state verification, and per-visitor namespace isolation in the session store. This allows attackers to forge session entries and gain unauthorized access. The vulnerability affects versions up to 1.7.27 and can be exploited by unauthenticated attackers. Successful exploitation requires that the target site has at least one social provider configured. Defenders should assess exposure, apply patches, and monitor for suspicious activity.
Defensive priority
High priority for WordPress administrators and defenders to assess exposure and apply patches
Recommended defensive actions
- Assess exposure by checking if the WPCOM Member plugin version is 1.7.27 or earlier
- Apply patches or updates to the WPCOM Member plugin to address the vulnerability
- Monitor for suspicious activity related to social-login callback handlers
- Verify social provider configurations and consider additional security measures
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability exists due to lack of nonce validation, OAuth state verification, and per-visitor namespace isolation in the session store, allowing attackers to forge session entries and gain unauthorized access.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104803 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104803
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104803 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104803
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Parameters
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104803.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/social-login.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/class-sesstion.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpcom-member/trunk/includes/social-login.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.