{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/woocommerce---social-login--2.8.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-8457"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WooCommerce - Social Login (\u003c= 2.8.7)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WooCommerce - Social Login plugin for WordPress, in versions up to and including 2.8.7, is affected by a critical authentication bypass vulnerability (CVE-2026-8457). The flaw resides in the plugin's Apple login handler, which decodes the base64 payload of an Apple id_token without performing mandatory cryptographic signature verification. Additionally, the plugin fails to validate critical JWT claims, including the issuer, audience, and expiration.\u003c/p\u003e\n\u003cp\u003eDefenders should note that the security nonce required to initiate the login flow is exposed to unauthenticated users within a localized JavaScript object on the login page. By combining the known nonce with a crafted id_token containing a target victim's email address, an attacker can coerce the application into resolving the target account and establishing an active, authenticated session. This allows for full account takeover of any registered WordPress user, including those with administrative privileges, without requiring existing credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain unauthorized administrative access to affected WordPress installations. This leads to complete site compromise, data exfiltration, the ability to modify or delete content, and the potential for further server-side code execution via administrative plugin or theme management features. The vulnerability affects all sites running versions 2.8.7 or earlier of the WooCommerce - Social Login plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WooCommerce - Social Login plugin to the latest available version beyond 2.8.7 immediately.\u003c/li\u003e\n\u003cli\u003eReview WordPress access logs for anomalous authentication events or successful logins originating from unusual IP addresses immediately following the identification of the vulnerability.\u003c/li\u003e\n\u003cli\u003eAudit user roles and administrative accounts for any unauthorized changes or newly created accounts that may indicate post-exploitation activity.\u003c/li\u003e\n\u003cli\u003eIf patching is not immediately feasible, disable the Apple social login functionality within the plugin settings to mitigate the primary exploitation vector.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-02T01:08:09Z","date_published":"2026-08-02T01:08:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-woocommerce-auth-bypass/","summary":"The WooCommerce - Social Login plugin for WordPress contains an authentication bypass vulnerability (CVE-2026-8457) that allows unauthenticated attackers to log in as any user, including administrators, via forged Apple ID tokens.","title":"Authentication Bypass Vulnerability in WooCommerce Social Login Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-woocommerce-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - WooCommerce - Social Login (\u003c= 2.8.7)","version":"https://jsonfeed.org/version/1.1"}