A critical security vulnerability has been discovered in the WooCommerce Social Login WordPress plugin, potentially allowing unauthorised attackers to gain access to ecommerce websites without needing any existing user permissions.

The vulnerability, rated 9.8 out of 10 in severity, affects plugin versions up to and including 2.8.7 and could allow attackers to log in as any registered user, including website administrators.

Vulnerability Found in WooCommerce Social Login Plugin

The WooCommerce Social Login plugin is designed to simplify the login process for online shoppers by allowing customers to access stores using third-party accounts from platforms such as Google, Facebook, Apple, Amazon and PayPal.

By enabling one-click authentication, the plugin helps customers complete purchases more quickly without creating separate store accounts.

However, researchers found a serious flaw within the plugin’s Apple login authentication process, which could be exploited to bypass normal security checks.

Attackers Could Access Administrator Accounts

The issue occurs because the plugin does not properly verify Apple identity tokens during login attempts.

When users sign in with Apple, the service provides an identity token containing account information. This token should be validated using Apple’s public keys to confirm that it is genuine.

However, the vulnerable plugin fails to properly confirm the authenticity of this information. As a result, attackers could submit a forged token containing the email address of an existing WordPress user and gain access to that account.

Security firm Wordfence explained that this could allow unauthorised users to log in as any existing WordPress account, including administrators, by manipulating the email information used during authentication.

Because administrator accounts are also affected, a successful exploit could give attackers complete control over a WooCommerce website, allowing them to manage settings, content and customer data.

Users Advised to Update Immediately

The vulnerability has been identified as CVE-2026-8457 and was publicly disclosed on 1 August 2026.

Wordfence has advised users running affected versions of the WooCommerce Social Login plugin to update to version 2.8.8 or later to protect their websites from potential attacks.

Website owners using WooCommerce should ensure their plugins are regularly updated, as outdated extensions can create serious security risks for online stores.

 

More Digital Marketing BLOGS here: 

Local SEO 2024 – How To Get More Local Business Calls

3 Strategies To Grow Your Business

Is Google Effective for Lead Generation?

What is SEO and How It Works?

How To Get More Customers On Facebook Without Spending Money

How Do I Get Clients Fast On Facebook?

How Do I Retarget Customers?

How Do You Use Retargeting In Marketing?

How To Get Clients From Facebook Groups

What Is The Best Way To Generate Leads On Facebook?

How Do I Get Leads From A Facebook Group?

>