WooCommerce Social Login Plugin Flaw Allows Full Site Takeover

Saeed Ashif Ahmed Saeed Ashif Ahmed · · 2 min read

Share this article

A critical security flaw in the WooCommerce Social Login WordPress plugin allows unauthenticated attackers to gain full control of affected websites, security researchers reported Tuesday.

The vulnerability, identified as CVE-2026-8457, is an authentication bypass that enables malicious actors to log in as any existing user, including site administrators. This flaw impacts all versions of the plugin up to and including 2.8.7.

Security firm Wordfence reported that the vulnerability carries a severity rating of 9.8 out of 10, underscoring the high risk it poses to websites utilizing the plugin.

The core issue resides within the plugin’s handler for Apple logins. It fails to adequately validate identity tokens issued by Apple, thereby allowing attackers to bypass authentication checks.

WooCommerce Social Login integrates various social media platforms such as Facebook, Google, Amazon and PayPal, alongside Apple, to facilitate user logins on e-commerce sites.

Wordfence advised all users of the affected plugin to update immediately to version 2.8.8 or higher to mitigate the risk of exploitation. The company stated that the update addresses the validation flaw.

The vulnerability could allow an attacker to impersonate an administrator, potentially leading to a complete compromise of the website, including data theft, defacement or the injection of malicious code.

Website administrators are urged to verify their plugin versions and apply the necessary updates to safeguard their online stores and user data.


Saeed Ashif Ahmed

Written by

Saeed Ashif Ahmed

I’m Saeed, the CTO of Rabbit Rank, with over a decade of experience in Blogging and SEO since 2010. Partner with us to ensure your project is handled with quality and expertise.

Keep reading

Related Articles

Ready to Dominate Search Results?

Let our experts analyze your website and create a custom SEO strategy that drives real results.