WooCommerce Social Login WordPress Plugin Enables Full Site Takeover via @sejournal, @martinibuster
Webinar How Freshpet Earned AI's Trust The GEO playbook behind Freshpet's AI Overview citations, plus checks to run on your own brand. Free, live Aug 20. Guide Local Google Visibility Guide + Cheat Sheet Track how your business appears across Google Search, Maps, and Gemini. Listings, reviews, and competitor signals all in one view. Webinar How Freshpet Earned AI's Trust The GEO playbook behind Freshpet's AI Overview citations, plus checks to run on your own brand. Free, live Aug 20. Rundown Why Your Brand Drops Out of AI Answers Five articles on the signals behind citation fluctuation, where models source citations, and how to audit your content for AI visibility gap Webinar New AI Search & SEO KPIs: 4 Real Signals AI mentions and citations are benchmarks, not decisions. Get 4 traffic-predictive signals drawn from real bot data across hundreds of sites. 🔥SEJ Pro Course: Own Your Brand’s Promo Code & Coupon Search Results Before Parasites Do WooCommerce Social Login WordPress plugin enables unauthenticated attackers to gain complete control of ecommerce sites. SEJ STAFF Roger Montti 6 hours ago ⋅ 2 min read SEJ STAFF Roger Montti Owner - Martinibuster.com at Martinibuster.com Bio Follow A critical vulnerability in the WooCommerce Social Login WordPress plugin enables unauthenticated attackers to log in as any existing user, including an administrator. The authentication bypass vulnerability is rated 9.8 out of 10 and affects all versions up to and including 2.8.7. The WooCommerce Social Login plugin enables frictionless one-click login for ecommerce store customers and enables fast checkout using accounts from services such as Facebook, Google, Amazon, PayPal, and Apple. This vulnerability is especially concerning because attackers do not need to acquire any user permission role to exploit it. The vulnerability affects the plugin’s Apple login handler, which processes the information received when someone signs in with an Apple account. Apple provides an identity token containing information about the person attempting to log in. The token is protected by a digital signature that should be checked against Apple’s public keys to confirm that it is authentic. This is where the plugin fails, enabling attackers to provide the email address of an existing user and gain access to that account. “This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying a forged id_token whose payload contains the target user’s email address, as that email is used without any role exclusion to resolve a WordPress account and immediately issue an authenticated session for it.” Because administrator accounts are not excluded from this exploit, a successful attack could provide administrative access to the WooCommerce site that uses this plugin. The vulnerability was assigned the Common Vulnerabilities and Exposures identifier CVE-2026-8457 and publicly disclosed on August 1, 2026. Wordfence recommends that users of versions up to and including 2.8.7 should update to version 2.8.8 or higher version. Read Full Bio SEJ STAFF Roger Montti Owner - Martinibuster.com at Martinibuster.com I have 25 years hands-on experience in SEO, evolving along with the search engines by keeping up with the latest ... Learn how to connect search, AI, and PPC into one unstoppable strategy. WooCommerce SEO: The Definitive Guide For Your Online Store How Do You Resolve A WordPress Plugin Conflict? Is WordPress The Right Choice For eCommerce Websites? Join 75,000+ Digital Leaders. Learn how to connect search, AI, and PPC into one unstoppable strategy. Learn how to connect search, AI, and PPC into one unstoppable strategy. In a world ruled by algorithms, SEJ brings timely, relevant information for SEOs, marketers, and entrepreneurs to optimize and grow their businesses -- and careers.
Source: Search Engine Journal
This article has been carefully curated and reformatted for educational and informational purposes. Full credit goes to the original publisher.
📚 Visit more helpful articles on Joab Peters Blog
No comments