THREAT OPS › Threat News › [NVD] CVE-2026-8457 (CRITICAL 9.8) — The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signat
[NVD] CVE-2026-8457 (CRITICAL 9.8) — The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signat
CVE-2026-8457 CVSS: 9.8 CRITICAL Published: 2026-08-02T00:16:23.047
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or validating the i
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-8457cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-8457