Product
An authentication bypass vulnerability (CVE-2026-104803) in the WPCOM Member WordPress plugin allows unauthenticated attackers to hijack user sessions, including administrative accounts, by exploiting insufficient nonce and session validation in the social-login callback handler.