<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>WooCommerce - Social Login (&lt;= 2.8.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/woocommerce---social-login--2.8.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 02 Aug 2026 01:08:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/woocommerce---social-login--2.8.7/feed.xml" rel="self" type="application/rss+xml"/><item><title>Authentication Bypass Vulnerability in WooCommerce Social Login Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-woocommerce-auth-bypass/</link><pubDate>Sun, 02 Aug 2026 01:08:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-woocommerce-auth-bypass/</guid><description>The WooCommerce - Social Login plugin for WordPress contains an authentication bypass vulnerability (CVE-2026-8457) that allows unauthenticated attackers to log in as any user, including administrators, via forged Apple ID tokens.</description><content:encoded><![CDATA[<p>The WooCommerce - Social Login plugin for WordPress, in versions up to and including 2.8.7, is affected by a critical authentication bypass vulnerability (CVE-2026-8457). The flaw resides in the plugin's Apple login handler, which decodes the base64 payload of an Apple id_token without performing mandatory cryptographic signature verification. Additionally, the plugin fails to validate critical JWT claims, including the issuer, audience, and expiration.</p>
<p>Defenders should note that the security nonce required to initiate the login flow is exposed to unauthenticated users within a localized JavaScript object on the login page. By combining the known nonce with a crafted id_token containing a target victim's email address, an attacker can coerce the application into resolving the target account and establishing an active, authenticated session. This allows for full account takeover of any registered WordPress user, including those with administrative privileges, without requiring existing credentials.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain unauthorized administrative access to affected WordPress installations. This leads to complete site compromise, data exfiltration, the ability to modify or delete content, and the potential for further server-side code execution via administrative plugin or theme management features. The vulnerability affects all sites running versions 2.8.7 or earlier of the WooCommerce - Social Login plugin.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the WooCommerce - Social Login plugin to the latest available version beyond 2.8.7 immediately.</li>
<li>Review WordPress access logs for anomalous authentication events or successful logins originating from unusual IP addresses immediately following the identification of the vulnerability.</li>
<li>Audit user roles and administrative accounts for any unauthorized changes or newly created accounts that may indicate post-exploitation activity.</li>
<li>If patching is not immediately feasible, disable the Apple social login functionality within the plugin settings to mitigate the primary exploitation vector.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>