CVE-2026-8457: authentication bypass in WPWeb WooCommerce - Social Login

Unauthenticated attackers can log in as any existing WordPress account — including administrators — on sites using the WooCommerce - Social Login plugin, allowing full account takeover (CVE-2026-8457). Versions affected are branch 2.x, 2.8.7 and earlier. The flaw is in the Apple login handler accepting a manipulated id_token without signature or claim validation while a security nonce is exposed to unauthenticated visitors, so no prior account or user interaction is required beyond supplying a forged token.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00704
CWE
CWE-289
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is critical because the flaw lets unauthenticated actors obtain administrator sessions; immediately remove or disable the Apple social-login provider or the plugin until a vendor fix is available.

What is CVE-2026-8457?

Unauthenticated attackers can log in as any existing WordPress account — including administrators — on sites using the WooCommerce - Social Login plugin, allowing full account takeover (CVE-2026-8457). Versions affected are branch 2.x, 2.8.7 and earlier. The flaw is in the Apple login handler accepting a manipulated id_token without signature or claim validation while a security nonce is exposed to unauthenticated visitors, so no prior account or user interaction is required beyond supplying a forged token.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of WPWeb WooCommerce - Social Login are affected?

BRANCHAFFECTEDFIXED
2.x2.8.7 and earlier

Is CVE-2026-8457 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-8457

  1. Disable the Apple provider in the WooCommerce - Social Login plugin or deactivate the plugin site-wide.
  2. Restrict access to the plugin's public endpoints and remove any localized JavaScript objects that expose login nonces if feasible.
  3. Monitor authentication and administrative login logs for unexpected sessions or new administrator accounts.
  4. Apply vendor security updates as soon as a patched release is published.

Frequently asked questions

Is CVE-2026-8457 being actively exploited?

There are no public reports of active exploitation of CVE-2026-8457 as of 2026-09-29.

Which WooCommerce - Social Login versions are affected by CVE-2026-8457?

The vulnerability affects WooCommerce - Social Login branch 2.x, specifically version 2.8.7 and earlier.

Is there a patch for CVE-2026-8457?

No patch is available as of 2026-09-29; follow the vendor for an official update and apply it promptly when released.

Does CVE-2026-8457 require authentication?

No — the issue can be exploited by unauthenticated attackers by supplying a forged Apple id_token.

References