Critical WooCommerce Social Login Flaw Lets Attackers Hijack Any Account via Forged Apple JWT
Wordfence disclosed a critical authentication bypass vulnerability (CVE-2026-8457, CVSS 9.8) on August 1, 2026, affecting the WooCommerce Social Login plugin by WPWeb Elite, versions up to 2.8.7. The flaw exists in the plugin's Apple login handler, which decodes a JWT token's payload without verifying its signature, issuer, audience, or expiry — allowing an attacker to forge a token containing any user's email and gain immediate authenticated access. Compounding the issue, the login security nonce is publicly exposed to unauthenticated users via a JavaScript object on the login page, removing any remaining client-side barrier. Security researcher Rafie Muhammad of Patchstack discovered and reported the flaw, which has been patched in version 2.8.8. This is the third high-to-critical authentication bypass logged for the same plugin family since 2024, all sharing a common pattern of trusting token claims without proper verification.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in