SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77002

CRITICAL · CVSS 9.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The SmilePass Selfie Login plugin for WordPress versions up to 1.0.2 is vulnerable due to a lack of server-side identity verification, enabling unauthenticated users to gain access to any registered account, including those with administrative privileges. This poses a significant security risk, as it could lead to unauthorized access and potential compromise of sensitive data. WordPress site administrators using this plugin should prioritize immediate updates or removal to mitigate the risk of exploitation.

CVE
CVE-2026-77002
Severity
CRITICAL
CVSS
9.8
EPSS
0.34%
WordPress

Original NVD Description

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.