Sceawere
Vulnerability Detail
CVE-2026-104803UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WPCOM Member Authentication Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 2h ago
- Vendor
- whyun
- Product
- WPCOM Member
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability exists because the `login` function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation in the session store, allowing an unauthenticated attacker to issue a crafted GET request that writes an attacker-named, attacker-valued entry into the global session namespace (bypassing the per-visitor prefix by prepending an underscore), then issue a second GET request triggering `weapp_new_user()` to read that forged entry and resolve the attacker-supplied `openid` value to a bound WordPress account before `wp_set_auth_cookie()` establishes a fully authenticated session. This makes it possible for unauthenticated attackers to log in as any WordPress user — including administrators — whose bound social provider identifier (openid/unionid) is known or discoverable. Successful exploitation requires that the target site has at least one social provider configured (which activates the vulnerable handler) and that the attacker knows or can enumerate the victim account's bound openid or unionid.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-10T08:17:04.210Z",
"pubdate": "2026-10-10T08:17:04.210Z",
"executiveSummary": "The WPCOM Member plugin for WordPress is susceptible to an Authentication Bypass vulnerability, identified in all versions up to and including 1.7.27.\nThe vulnerability stems from flawed social-login callback handling via the 'init' hook, specifically within the 'login' function.\nBy neglecting nonce validation, OAuth state verification, and namespace isolation in the session store, the plugin allows unauthenticated attackers to manipulate global session entries.\nAn attacker can exploit this flaw to impersonate any WordPress user, including those with administrative privileges, provided they can identify or enumerate the victim's bound social provider identifier (openid or unionid).\nThis vulnerability is critical, as it bypasses standard authentication protocols without requiring prior credentials.\nSuccessful exploitation requires that at least one social provider be configured on the target site to activate the vulnerable handler.\nThe risk implication is total site compromise if an administrator account is targeted, as the attacker gains full authenticated access to the target WordPress environment.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of the social-login callback handler registered on the 'init' hook within the WPCOM Member plugin. The 'login' function fails to implement essential security controls, including CSRF protection via nonces, OAuth 'state' parameter verification, and secure namespace isolation within the global session store.\nThe exploitation process involves a multi-stage request sequence. In the first phase, an unauthenticated attacker issues a crafted GET request utilizing the 'uuid' and 'code' parameters. Because the session store fails to enforce per-visitor namespace isolation—specifically by allowing the prefixing of an underscore to overwrite or define keys in the global namespace—the attacker can inject a malicious entry containing an attacker-controlled 'openid' value.\nIn the second phase, the attacker triggers the 'weapp_new_user()' function. This function retrieves the forged session entry created in the previous step. The application logic then resolves the attacker-supplied 'openid' or 'unionid' to an existing WordPress account associated with that identifier. Because this resolution occurs before the 'wp_set_auth_cookie()' function is called to finalize the authentication state, the application incorrectly trusts the forged session data.\nBy successfully masquerading as a legitimate user, the attacker effectively bypasses the authentication gate. The vulnerability is highly exploitable provided the target site has enabled social login functionality, which activates the vulnerable code path. The attacker requires knowledge of the target's bound identifier; however, these identifiers are often discoverable or enumerable depending on the social provider's integration and the site's configuration.\nThe impact is significant: the attacker gains authorized access to the account associated with the identifier, leading to full session hijacking. If the compromised identifier belongs to a site administrator, the attacker achieves full administrative control over the WordPress installation. This flaw represents a severe failure in session management and authentication flow verification, circumventing the intended security boundary between public access and authenticated sessions."
}