Horizon Alert
Summary of the vulnerability and why it matters
A security issue has been identified in the WPCOM Member plugin for WordPress that could allow an unauthenticated attacker to bypass normal login procedures. This vulnerability affects how the plugin handles social login callbacks, potentially enabling unauthorized access to user accounts, including administrator privileges, if specific social provider identifiers are known. The main concern is confirming whether this plugin is in use and if any social login providers are configured on affected systems.
- Unauthenticated attackers can bypass logins.
- Affects WordPress sites using social login.
- Confirm plugin use and social login configuration.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can bypass login protections by exploiting the social login feature in the WPCOM Member plugin. By sending specially crafted requests, an attacker can manipulate the session data to associate their session with any WordPress user whose social provider identifier is known or can be discovered. This allows the attacker to then establish an authenticated session as that user, potentially gaining administrative privileges.
- No authentication required.
- Crafted GET requests to the social-login callback.
- Full account takeover, including administrative access.
Live Threat
Current exploitation, exposure, and threat context
When a WordPress site uses the WPCOM Member plugin with social login enabled, an unauthenticated attacker could bypass authentication. This occurs by exploiting weaknesses in how the plugin handles social login callbacks, allowing an attacker to craft requests that impersonate any user whose social provider identifier is known or discoverable.
- WordPress user accounts with configured social providers.
- Through crafted requests to the social-login callback handler.
- Unauthenticated attackers could gain administrative access.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners and platform teams are likely responsible for addressing this vulnerability in the WPCOM Member plugin. The immediate first step is to identify all WordPress instances using this plugin, confirm if the social login feature is active, and determine if any user identities are exposed. Once identified, the accountable owner should be notified to plan remediation, potentially involving vendor coordination or temporary risk reduction if immediate patching is not feasible.
- Accountable owners must identify plugin instances.
- Verify social login activation and user exposure.
- Plan remediation based on identified risks.