If your WooCommerce store uses the Social Login plugin, you have a critical security hole that lets attackers log in as any user—including an administrator—without a password. The flaw, rated 9.8 out of 10, affects all versions up to and including 2.8.7. Update to 2.8.8 immediately.
This vulnerability was publicly disclosed on August 1, 2026, and assigned CVE-2026-8457. It's a textbook authentication bypass: the plugin's Apple login handler fails to verify the digital signature on Apple's identity token, so an attacker can forge a token with any email address and gain instant access to that account.
What This Means for Your Business
If you run a WooCommerce store with this plugin, your entire site—customer data, orders, payment information—is at risk. An attacker who logs in as an admin can install malicious plugins, redirect traffic, or steal sensitive data. Even if you don't use Apple login, the plugin is vulnerable if it's active.
This isn't a theoretical risk. The exploit requires no user interaction, and attackers are actively scanning for vulnerable sites. The Wordfence team, who discovered the flaw, noted: "This makes it possible for unauthenticated attackers to log in as any existing WordPress user—including administrators—by supplying a forged id_token whose payload contains the target user's email address."
Who's Affected
Any WooCommerce store with the Social Login plugin version 2.8.7 or lower is vulnerable. If you're not sure which version you have, check your WordPress admin under Plugins. If you've disabled the plugin, you're still at risk if it's installed—attackers can sometimes exploit inactive plugins.
If you don't use this plugin, you can ignore this specific threat, but it's a reminder to audit all plugins for similar issues.
Your Move: Update Now
Go to your WordPress dashboard, navigate to Plugins, and update WooCommerce Social Login to version 2.8.8 or higher. If you can't update immediately, deactivate the plugin until you can. This is a five-minute fix that could save your business from a devastating breach.
After updating, review your site's user accounts for any suspicious new admins. Change your admin passwords and enable two-factor authentication for extra security.
This incident underscores the importance of keeping plugins updated and monitoring security advisories. Consider enabling automatic updates for critical plugins and using a security plugin like Wordfence to block malicious traffic.
FAQ
Attackers forge an Apple identity token with the email of any user, and the plugin fails to verify the token's signature, granting instant access to that account—including admins.
Update to version 2.8.8 or higher immediately. If you can't update, deactivate the plugin until you can. Also, check for any unauthorized admin accounts and change your passwords.


