Authentication Bypass Vulnerability in WPCOM Member Plugin
An authentication bypass vulnerability (CVE-2026-104803) in the WPCOM Member WordPress plugin allows unauthenticated attackers to hijack user sessions, including administrative accounts, by exploiting insufficient nonce and session validation in the social-login callback handler.
CVE search metadata
CVE search record: CVE-2026-104803. Severity: critical. CVSS: 9.8. KEV: no. Product: WPCOM Member (<= 1.7.27). Brief: Authentication Bypass Vulnerability in WPCOM Member Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wpcom-auth-bypass/
The WPCOM Member plugin for WordPress (versions 1.7.27 and below) is susceptible to a critical authentication bypass vulnerability, assigned CVE-2026-104803. The flaw resides in the social-login callback handler, which is registered on the WordPress 'init' hook. Because the plugin fails to perform nonce validation, lacks OAuth state verification, and does not enforce per-visitor namespace isolation in its session storage, the plugin is prone to session manipulation.
An unauthenticated attacker can supply crafted 'uuid' and 'code' parameters via a GET request to inject arbitrary values into the global session store. By manipulating these parameters, the attacker forces the plugin's 'weapp_new_user()' function to associate a target user's known or discoverable 'openid' with a session forged by the attacker. This allows the attacker to impersonate any user, including site administrators, and establish a legitimate authentication cookie. This vulnerability requires at least one social provider to be configured on the target site for the vulnerable code path to be active.
Impact
Successful exploitation allows unauthenticated attackers to gain unauthorized access to any WordPress account on the affected site. If an attacker targets an account with administrative privileges and has discovered the associated social provider identifier, they can achieve full site takeover, potentially leading to unauthorized data exfiltration, malicious plugin installation, or site-wide compromise.
Recommendation
- Upgrade the WPCOM Member plugin to a version patched against CVE-2026-104803 immediately.
- Until patching is possible, disable the social-login functionality within the WPCOM Member plugin configuration to deactivate the vulnerable callback handler.
- Review WordPress access logs for anomalous GET requests directed at the plugin's callback endpoints containing unusual 'uuid' or 'code' query strings.
- Audit existing user accounts for suspicious modifications or unauthorized login events.
Immediate actions
Patch WPCOM Member to a version > 1.7.27 or disable social-login features.
Threat Hunt
Search web logs for high frequency of GET requests containing 'uuid' and 'code' parameters from single IPs.
Data: Web server access logs
Mitigations
Disable social-login handlers in WPCOM Member plugin settings.
CVE-2026-104803
Detection coverage 1
Detect CVE-2026-104803 Exploitation - Suspicious Callback Parameters
criticalDetects potential exploitation attempts of CVE-2026-104803 by flagging GET requests to common WordPress social-login patterns that contain suspicious or excessively long UUID and code parameters.
Detection queries are available on the platform. Get full rules →