SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77000

CRITICAL · CVSS 9.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The WP Social Media Login plugin for WordPress versions up to 1.0.6 is vulnerable due to a lack of verification for social login completions, enabling unauthenticated attackers to gain access to any existing user account, including those of administrators, by simply providing the user's email address. This poses a significant security risk, particularly for sites with elevated privileges or sensitive data. WordPress site administrators using this plugin should prioritize immediate updates or mitigations to prevent unauthorized access.

CVE
CVE-2026-77000
Severity
CRITICAL
CVSS
9.8
EPSS
0.34%
WordPress

Original NVD Description

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.