CVE-2026-12597Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array returned by GitHub's /user/emails endpoint as an account-binding identifier without verifying that the email carries a verified === true status. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by adding an unverified email address matching a local account to their GitHub profile and triggering the OAuth callback via a crafted code parameter — causing the plugin to call get_user_by('email', ...) and establish an authenticated session for the matched account. Practical exploitation is conditional on GitHub returning the attacker-added unverified email at index 0 of the /user/emails response, as GitHub typically prioritizes the primary verified address first; nonetheless, the absence of any email verification check in the plugin constitutes a fundamental authentication bypass flaw.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-10: 3Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 307-10
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • ADK Cyber@ADKCyber
    Patch

    WordPress sites using LoginPress Pro 6.2.3 or earlier face CVE-2026-12597 (CVSS 8.1) auth bypass. Update the plugin now. http://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/p3AqZodJNP

    Post summary

    WordPress sites running LoginPress Pro version 6.2.3 or earlier are vulnerable to CVE-2026-12597, a high‑score authentication bypass that requires updating the plugin.

    0000056
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12597 The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerabilit… https://www.cve.org/CVERecord?id=CVE-2026-12597

    Post summary

    The post announces that LoginPress Pro 6.2.3 and earlier suffer an authentication bypass via GitHub OAuth, but contains no PoC, exploit code, or mitigation details.

    00000702
    57.8K followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 CRITICAL: LoginPress Pro 3-CVE Cluster — CVSS 8.1 x3 CVE-2026-12595: OAuth auth bypass (unverified email) CVE-2026-12597: OAuth auth bypass (GitHub callback) CVE-2026-12598: OAuth auth bypass (Spotify addon) → http://threataft.com/articles/loginpress-pro-cve-2026-12595-12597-12598 #cybersecurity #infosec #WordPress

    Post summary

    The post discloses a cluster of OAuth bypass CVEs for LoginPress Pro with CVSS 8.1 and provides a link to an article, but offers no exploit code, patches, or evidence of active exploitation.

    0000096
    34 followersView on X

Explore more