CVE-2026-77000 PUBLISHED

WP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter Login Flow

Assigner: WPScan
Reserved: 20.08.2026 Published: 22.08.2026 Updated: 22.08.2026

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.

Product Status

Vendor Unknown
Product WP Social Media Login
Versions Default: unknown
  • affected from 0 to 1.0.6 (incl.)

Credits

  • Khaled Alenazi (Nxploited) finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE