CVE-2026-104803 - WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Parameters on Social-Login Callback
CVE ID :CVE-2026-104803 Published : Oct. 10, 2026, 8:17 a.m. | 1 hour, 13 minutes ago Description :The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback...