Authentication Bypass Vulnerability in WPCOM Member Plugin for WordPress
CVE-2026-104803
What is CVE-2026-104803?
The WPCOM Member plugin for WordPress is susceptible to an authentication bypass through the social-login callback handler. This vulnerability allows unauthenticated attackers to manipulate the uuid and code parameters to issue crafted GET requests that write unauthorized entries into the global session namespace. The absence of nonce validation and OAuth state verification means that attackers can exploit this issue, especially if they are aware of the target user’s social provider identifier (openid/unionid). By triggering the weapp_new_user() function with forged session data, an attacker can log in as any WordPress user, including those with administrative privileges, provided that the victim's social account is configured on the affected site.
Affected Version(s)
WPCOM Member 0 <= 1.7.27