Authentication Bypass Vulnerability in WPCOM Member Plugin for WordPress
CVE-2026-104803

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-104803?

The WPCOM Member plugin for WordPress is susceptible to an authentication bypass through the social-login callback handler. This vulnerability allows unauthenticated attackers to manipulate the uuid and code parameters to issue crafted GET requests that write unauthorized entries into the global session namespace. The absence of nonce validation and OAuth state verification means that attackers can exploit this issue, especially if they are aware of the target user’s social provider identifier (openid/unionid). By triggering the weapp_new_user() function with forged session data, an attacker can log in as any WordPress user, including those with administrative privileges, provided that the victim's social account is configured on the affected site.

Affected Version(s)

WPCOM Member 0 <= 1.7.27

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mohamed Khater
.