WPCOM Member Authentication Bypass via Social Login Callback
WPCOM Member plugin authentication bypass via uuid and code parameters in the social login callback. Any registered account is takeover-able. CVSS 9.8. Fix in 1.7.28.
- Vendor
- WPCOM
- Product
- WPCOM Member
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
WPCOM Member, a membership plugin for WordPress and WooCommerce, had an authentication bypass in all versions up to and including 1.7.27.
The vulnerability is in the social login callback handler. When a user logs in via a social OAuth provider, the plugin’s callback handler receives a uuid and code parameter and uses them to authenticate the corresponding account. The flaw: the handler does not verify that the uuid and code values came from an actual OAuth exchange with the configured provider. An attacker who knows a valid UUID for any registered user can call the callback with that UUID directly, bypassing the OAuth flow and authenticating as the target user.
User UUIDs may be enumerable or guessable depending on how the application generates and exposes them. The attack requires no prior authentication and no interaction from the target user.
On a WooCommerce store, a compromised session gives the attacker access to anything the account can reach: order history, stored addresses, saved payment methods if retained by the payment gateway, and any membership-level privileges.
Fix is in version 1.7.28 or later. Apply the update through the WordPress dashboard or via wp plugin update wpcom-member.
In the same disclosure batch: CVE-2026-103889 (3D Product Configurator RCE, CVSS 9.8) and CVE-2026-104801 (PPOM Product Addons file deletion, CVSS 9.1). See the full coverage article for remediation priority.
For broader WooCommerce and WordPress plugin coverage, see the WordPress topic hub.
