<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WPCOM Member (&lt;= 1.7.27) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wpcom-member--1.7.27/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 09:51:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wpcom-member--1.7.27/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass Vulnerability in WPCOM Member Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-wpcom-auth-bypass/</link><pubDate>Sat, 10 Oct 2026 09:51:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wpcom-auth-bypass/</guid><description>An authentication bypass vulnerability (CVE-2026-104803) in the WPCOM Member WordPress plugin allows unauthenticated attackers to hijack user sessions, including administrative accounts, by exploiting insufficient nonce and session validation in the social-login callback handler.</description><content:encoded><![CDATA[<p>The WPCOM Member plugin for WordPress (versions 1.7.27 and below) is susceptible to a critical authentication bypass vulnerability, assigned CVE-2026-104803. The flaw resides in the social-login callback handler, which is registered on the WordPress 'init' hook. Because the plugin fails to perform nonce validation, lacks OAuth state verification, and does not enforce per-visitor namespace isolation in its session storage, the plugin is prone to session manipulation.</p>
<p>An unauthenticated attacker can supply crafted 'uuid' and 'code' parameters via a GET request to inject arbitrary values into the global session store. By manipulating these parameters, the attacker forces the plugin's 'weapp_new_user()' function to associate a target user's known or discoverable 'openid' with a session forged by the attacker. This allows the attacker to impersonate any user, including site administrators, and establish a legitimate authentication cookie. This vulnerability requires at least one social provider to be configured on the target site for the vulnerable code path to be active.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain unauthorized access to any WordPress account on the affected site. If an attacker targets an account with administrative privileges and has discovered the associated social provider identifier, they can achieve full site takeover, potentially leading to unauthorized data exfiltration, malicious plugin installation, or site-wide compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the WPCOM Member plugin to a version patched against CVE-2026-104803 immediately.</li>
<li>Until patching is possible, disable the social-login functionality within the WPCOM Member plugin configuration to deactivate the vulnerable callback handler.</li>
<li>Review WordPress access logs for anomalous GET requests directed at the plugin's callback endpoints containing unusual 'uuid' or 'code' query strings.</li>
<li>Audit existing user accounts for suspicious modifications or unauthorized login events.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>authentication-bypass</category><category>web-vulnerability</category></item></channel></rss>