A critical authentication bypass vulnerability, tracked as CVE-2026-8457, affects the WooCommerce - Social Login WordPress plugin by WPWeb in all versions through 2.8.7. The flaw allows unauthenticated attackers to log in as any existing WordPress user, including administrators, by forging an Apple id_token JWT with a victim's email address. Researchers said the plugin's Apple login handler decodes the token payload but does not verify the JWT signature against Apple's public keys or validate core claims such as issuer, audience, and expiry.
The attack is further enabled by a login-flow nonce that is exposed to unauthenticated users through a localized JavaScript object on the login page. The issue has a CVSS 9.8 rating and is classified as CWE-289, reflecting the risk of full account takeover and complete site compromise when an administrator account is targeted. The vulnerability is fixed in 2.8.8, and public reporting said no active exploitation had been confirmed at the time of disclosure.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE entry states that the new CVE was received by security@wordfence.com. The record identifies the issue as CWE-289 and describes impact up to administrator account compromise.
CVE-2026-8457 was publicly disclosed as a critical authentication bypass in the WooCommerce - Social Login WordPress plugin. The flaw stems from accepting forged Apple id_token JWTs without proper signature and claim validation, enabling account takeover.
Version 2.8.8 of the WooCommerce - Social Login plugin was released to fix CVE-2026-8457. The issue affects all versions up to and including 2.8.7.
The authentication bypass vulnerability in the WooCommerce - Social Login plugin was discovered by Rafie Muhammad of Awesome Motive. The flaw affects the plugin's Apple login flow and can allow login as arbitrary existing users via a forged Apple id_token.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.