Unauthorized Access in Social Login & Sharing Plugin by SoClever for WordPress
CVE-2026-77001
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 August 2026
Badges
What is CVE-2026-77001?
The Social Login & Sharing buttons with Analytics plugin by SoClever, prior to version 1.2.0, contains a significant security flaw that lacks essential authentication, authorization, and nonce checks in its publicly accessible login handlers. This oversight enables unauthenticated attackers to exploit the vulnerability and gain a valid session as any existing user, including those with administrator privileges. In typical scenarios, attackers can compromise the site's original administrator account without any knowledge of account credentials, posing severe risks to user data and overall site integrity.
Affected Version(s)
Social Login & Sharing buttons with Analytics By SoClever 0 <= 1.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.