DIRAS TAKE
Urgent: this is critical because the flaw lets unauthenticated actors obtain administrator sessions; immediately remove or disable the Apple social-login provider or the plugin until a vendor fix is available.
What is CVE-2026-8457?
Unauthenticated attackers can log in as any existing WordPress account — including administrators — on sites using the WooCommerce - Social Login plugin, allowing full account takeover (CVE-2026-8457). Versions affected are branch 2.x, 2.8.7 and earlier. The flaw is in the Apple login handler accepting a manipulated id_token without signature or claim validation while a security nonce is exposed to unauthenticated visitors, so no prior account or user interaction is required beyond supplying a forged token.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of WPWeb WooCommerce - Social Login are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2.x | 2.8.7 and earlier |
Is CVE-2026-8457 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-8457
- Disable the Apple provider in the WooCommerce - Social Login plugin or deactivate the plugin site-wide.
- Restrict access to the plugin's public endpoints and remove any localized JavaScript objects that expose login nonces if feasible.
- Monitor authentication and administrative login logs for unexpected sessions or new administrator accounts.
- Apply vendor security updates as soon as a patched release is published.
Frequently asked questions
Is CVE-2026-8457 being actively exploited?
There are no public reports of active exploitation of CVE-2026-8457 as of 2026-09-29.
Which WooCommerce - Social Login versions are affected by CVE-2026-8457?
The vulnerability affects WooCommerce - Social Login branch 2.x, specifically version 2.8.7 and earlier.
Is there a patch for CVE-2026-8457?
No patch is available as of 2026-09-29; follow the vendor for an official update and apply it promptly when released.
Does CVE-2026-8457 require authentication?
No — the issue can be exploited by unauthenticated attackers by supplying a forged Apple id_token.
References
- nvd.nist.gov/vuln/detail/CVE-2026-8457
- cve.org/CVERecord?id=CVE-2026-8457
- wordfence.com/threat-intel/vulnerabilities/id/53e83037-2cc5-4dc9-b55d-03829df12a65?source=cve
- codecanyon.net/item/social-login-wordpress-woocommerce-plugin/8495883
- All WPWeb CVEs on CVE Radar
- CVEs published in September 2026