SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77001

CRITICAL · CVSS 9.8 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin versions up to 1.2.0 are vulnerable due to a lack of authentication, authorization, and nonce checks in a publicly accessible login handler. This flaw allows unauthenticated attackers to gain a valid session as any existing user, including administrators, potentially compromising the entire site. WordPress site administrators and users of this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.

CVE
CVE-2026-77001
Severity
CRITICAL
CVSS
9.8
EPSS
0.42%
WordPress

Original NVD Description

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obtained without needing to know any account details at all.