WooCommerce - Social Login

WooCommerce - Social Login has 10 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 10 are fixed as of September 2026. Their average CVSS score is 8.2, and the most serious one scores 9.8 out of 10. Severity breakdown: 5 critical and 3 high. 2024 was the busiest year with 8 disclosures.

The most common weakness is Authentication Bypass Using An Alternate Path Or Channel, behind 2 of the records (20%). Other recurring categories include Deserialization Of Untrusted Data, Authentication Bypass By Alternate Name.

Every one of the 10 issues recorded for WooCommerce - Social Login has a vendor fix available, so running the current release closes all known holes.

6 independent researchers contributed these findings, most of them (3) reported by Vu Nguyen (maxntv).

Strategic Overview

Avg CVSSHigh
8.2/ 10
Patch Coverage100%
Open

0

Fixed

10

Get automatic notifications for all WooCommerce - Social Login vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-8457

WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT

Read the full analysis

Vulnerability Records

10 records
2026-08-01 11:09CVE-2026-8457
9.8
Critical
Rafie MuhammadYes
2025-04-16 00:00CVE-2025-39472
4.3
Medium
Ananda DhakalYes
2024-11-04 00:00CVE-2024-10114
8.1
High
wesley (wcraft)Yes
2024-08-09 13:23CVE-2024-7503
9.8
Critical
Truoc PhanYes
2024-07-19 00:00CVE-2024-6637
7.3
High
Vu Nguyen (maxntv)Yes
2024-07-19 00:00CVE-2024-6635
7.3
High
Vu Nguyen (maxntv)Yes
2024-07-19 00:00CVE-2024-6636
9.8
Critical
Vu Nguyen (maxntv)Yes
2024-07-05 00:00CVE-2024-37502
9.8
Critical
Ananda DhakalYes
2024-06-14 00:00CVE-2024-5868
6.5
Medium
István MártonYes
2024-06-14 00:00CVE-2024-5871
9.8
Critical
István MártonYes
Showing 1–10 of 10 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C