What is CVE-2026-8457?
CVE-2026-8457 is an Authentication Bypass vulnerability in the WooCommerce-Social Login plugin for WordPress. The flaw exists in the Apple login handler, which fails to verify the JWT signature, allowing attackers to bypass authentication. All versions up to and including 2.8.7 are affected, and immediate plugin update is recommended.
Azərbaycanca: WordPress üçün WooCommerce-Social Login plaginində CVE-2026-8457 zəifliyi aşkar edilib. Bu, Apple giriş idarəedicisində JWT imzasının düzgün yoxlanılmaması səbəbindən autentifikasiya bypassına yol açır. Plaginin 2.8.7 və daha əvvəlki versiyaları təsirlənir, istifadəçilərə dərhal yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which component of the WooCommerce-Social Login plugin contains the CVE-2026-8457 vulnerability?
The CVE-2026-8457 vulnerability exists in the plugin's Apple login handler.
Which versions of the plugin are affected by this vulnerability?
All versions of the WooCommerce-Social Login plugin up to and including 2.8.7 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.