External risk intelligence

WPCOM Member Plugin Authentication Bypass Via Social Login

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-104803

The vulnerability resides in a WordPress plugin that handles social login functionality. Because this plugin provides a public-facing authentication feature on a website, it is commonly exposed to the internet to allow users to register or log in. The vulnerable callback handler is part of the standard web application flow accessible to any unauthenticated visitor.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue has been identified in the WPCOM Member plugin for WordPress that could allow an unauthenticated attacker to bypass normal login procedures. This vulnerability affects how the plugin handles social login callbacks, potentially enabling unauthorized access to user accounts, including administrator privileges, if specific social provider identifiers are known. The main concern is confirming whether this plugin is in use and if any social login providers are configured on affected systems.

  • Unauthenticated attackers can bypass logins.
  • Affects WordPress sites using social login.
  • Confirm plugin use and social login configuration.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can bypass login protections by exploiting the social login feature in the WPCOM Member plugin. By sending specially crafted requests, an attacker can manipulate the session data to associate their session with any WordPress user whose social provider identifier is known or can be discovered. This allows the attacker to then establish an authenticated session as that user, potentially gaining administrative privileges.

  • No authentication required.
  • Crafted GET requests to the social-login callback.
  • Full account takeover, including administrative access.

Live Threat

Current exploitation, exposure, and threat context

When a WordPress site uses the WPCOM Member plugin with social login enabled, an unauthenticated attacker could bypass authentication. This occurs by exploiting weaknesses in how the plugin handles social login callbacks, allowing an attacker to craft requests that impersonate any user whose social provider identifier is known or discoverable.

  • WordPress user accounts with configured social providers.
  • Through crafted requests to the social-login callback handler.
  • Unauthenticated attackers could gain administrative access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for addressing this vulnerability in the WPCOM Member plugin. The immediate first step is to identify all WordPress instances using this plugin, confirm if the social login feature is active, and determine if any user identities are exposed. Once identified, the accountable owner should be notified to plan remediation, potentially involving vendor coordination or temporary risk reduction if immediate patching is not feasible.

  • Accountable owners must identify plugin instances.
  • Verify social login activation and user exposure.
  • Plan remediation based on identified risks.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WPCOM Member plugin?

The WPCOM Member plugin is an add-on for WordPress websites designed to manage user accounts and simplify the login process. A core feature it offers is social login, which allows visitors to sign in or register using credentials from external platforms like Google, Facebook, or other identity providers rather than creating a unique username and password for the site.

What does CWE-287 mean for CVE-2026-104803?

CWE-287 refers to Improper Authentication. In this vulnerability, the plugin fails to properly verify the identity of a person attempting to log in through the social login feature. Because the system does not check critical security tokens or validate the legitimacy of the incoming request, it allows an attacker to manipulate the login flow and masquerade as another user.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending two specific web requests to the site. The first request injects forged data into the session memory, and the second request forces the plugin to use that fake data to authenticate. This process does not work if the site has social login disabled, as the vulnerable handler only executes when the plugin is actively configured to process social authentication callbacks.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal indicates that because this plugin provides a public-facing authentication feature, it is commonly exposed to the internet. If your WordPress site has the WPCOM Member plugin installed and at least one social provider enabled, your site is functionally exposed to this risk, as the callback handler is accessible to any visitor over the network.

What should I do if I run this plugin?

Your first step is to confirm whether the plugin is installed and verify if the social login feature is currently active. If it is, ensure you are aware of which user accounts are linked to social providers. Notify the team responsible for your website's maintenance to prioritize an update or take the affected component offline until a secure version is available.

References