
WooCommerce Social Login WordPress Plugin Enables Full Site Takeover via @sejournal, @martinibuster
- ●A severe vulnerability in the WooCommerce Social Login plugin allows unauthenticated attackers to log in as any WordPress user, including administrators.
- ●The flaw, rated 9.8 out of 10, arises from a failure in the plugin's Apple login handler to properly verify id_tokens, leading to an authentication bypass.
- ●Users are urged to update the plugin to version 2.8.8 or higher to secure their sites against this vulnerability.

















