{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awpcommember/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpcom:member:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-104803"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPCOM Member (\u003c= 1.7.27)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","authentication-bypass","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["WPCOM"],"content_html":"\u003cp\u003eThe WPCOM Member plugin for WordPress (versions 1.7.27 and below) is susceptible to a critical authentication bypass vulnerability, assigned CVE-2026-104803. The flaw resides in the social-login callback handler, which is registered on the WordPress 'init' hook. Because the plugin fails to perform nonce validation, lacks OAuth state verification, and does not enforce per-visitor namespace isolation in its session storage, the plugin is prone to session manipulation.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can supply crafted 'uuid' and 'code' parameters via a GET request to inject arbitrary values into the global session store. By manipulating these parameters, the attacker forces the plugin's 'weapp_new_user()' function to associate a target user's known or discoverable 'openid' with a session forged by the attacker. This allows the attacker to impersonate any user, including site administrators, and establish a legitimate authentication cookie. This vulnerability requires at least one social provider to be configured on the target site for the vulnerable code path to be active.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain unauthorized access to any WordPress account on the affected site. If an attacker targets an account with administrative privileges and has discovered the associated social provider identifier, they can achieve full site takeover, potentially leading to unauthorized data exfiltration, malicious plugin installation, or site-wide compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the WPCOM Member plugin to a version patched against CVE-2026-104803 immediately.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, disable the social-login functionality within the WPCOM Member plugin configuration to deactivate the vulnerable callback handler.\u003c/li\u003e\n\u003cli\u003eReview WordPress access logs for anomalous GET requests directed at the plugin's callback endpoints containing unusual 'uuid' or 'code' query strings.\u003c/li\u003e\n\u003cli\u003eAudit existing user accounts for suspicious modifications or unauthorized login events.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T09:51:02Z","date_published":"2026-10-10T09:51:02Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wpcom-auth-bypass/","summary":"An authentication bypass vulnerability (CVE-2026-104803) in the WPCOM Member WordPress plugin allows unauthenticated attackers to hijack user sessions, including administrative accounts, by exploiting insufficient nonce and session validation in the social-login callback handler.","title":"Authentication Bypass Vulnerability in WPCOM Member Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-wpcom-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wpcom:member:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}