External risk intelligence

SmilePass Selfie Login WordPress Plugin Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-77002

The vulnerability affects a WordPress plugin designed for user authentication. WordPress sites and their login portals are commonly deployed as public-facing web applications, making this functionality directly reachable from the internet.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security flaw in the SmilePass Selfie Login WordPress plugin allows anyone to log in as any user, including administrators, without needing proper authentication. This impacts how user identities are managed on WordPress sites. The main concern is confirming relevance and exposure.

  • Unauthenticated access to any account is possible.
  • It bypasses identity verification for user logins.
  • Confirm if this plugin is in use and exposed.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by accessing the plugin's functionality over the network without needing any credentials. This allows them to bypass the intended authentication process and gain access to any user account on the affected WordPress site. When this vulnerability is successfully triggered, it can lead to unauthorized access and control over the website.

  • No authentication required.
  • Submitting fake identity data.
  • Complete site takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated users to bypass login procedures and access any account on a WordPress site, including administrator accounts, when the SmilePass Selfie Login plugin is active. This could lead to unauthorized access and modification of site content and user data.

  • User accounts and site data at risk.
  • Unauthenticated access to login functionality.
  • Unauthorized control and data modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given this critical vulnerability in the SmilePass Selfie Login WordPress plugin, application owners and infrastructure teams must act quickly. The immediate first step is to identify all instances of this plugin across your WordPress deployments, determine their internet reachability and business criticality, and pinpoint the accountable owner for each instance before planning remediation.

  • Application owners and infrastructure teams.
  • Verify plugin presence and reachability.
  • Plan and execute targeted remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the SmilePass Selfie Login WordPress plugin?

SmilePass is an extension for WordPress sites that adds biometric authentication features, specifically allowing users to log into their accounts using facial recognition (selfies). It is designed to replace or supplement standard username and password logins to simplify user access while integrating directly into the WordPress user management system.

What does CWE-287 mean for CVE-2026-77002?

CWE-287 refers to Improper Authentication. In the context of this CVE, it means the plugin fails to verify the identity of the person attempting to log in. Because the system trusts the incoming login request without checking if it is genuine, it grants access to anyone who submits a request, regardless of whether they have a valid password or biometric data.

How can an attacker trigger this authentication bypass?

An attacker can trigger this vulnerability by interacting with the plugin's login network endpoint without providing legitimate credentials. They do not need to possess the actual biometric data or the password of the target user. Simply sending a crafted request to the plugin's authentication path is sufficient to trick the system into granting a session as any user, including administrators.

Why is this plugin considered internet-facing?

According to Halo Surface Signal, this vulnerability is highly relevant because the plugin handles user authentication for WordPress sites, which are almost exclusively designed to be reachable over the internet. Since the login page is a public-facing component required for user access, an attacker does not need internal network access to exploit this flaw.

Do I need to check my WordPress sites for this plugin?

Yes, you should immediately conduct an inventory to see if the SmilePass Selfie Login plugin is installed on your web servers. Once you identify all instances, confirm which sites are publicly accessible and verify if the plugin is currently active. Determining the scope of your footprint is the necessary first step to prioritize remediation for the most critical assets.

References