CVE-2026-8457Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-08-02); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-08-02: 5Mentions · 2026-08-07: 1Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-07: 1Technical Details · 2026-08-02: 4Technical Details · 2026-08-07: 108-0208-07
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-025
Disclosure4General1
2026-08-071
Patch1
Full discourse6 posts
  • Patrick DUHAUT - ONI@oni_sas
    Patch

    Faille WooCommerce : prise de contrôle totale via Social Login (CVE-2026-8457) WooCommerce Social Login peut offrir un accès admin sans mot de passe. Mettez à jour en urgence et vérifiez vos comptes. Plus d'infos dans le tweet épinglé #Sécurité #WooCommerce https://t.co/itdhQQlfIG

    Post summary

    A new WooCommerce Social Login flaw (CVE-2026-8457) grants admin access without passwords; users are urged to update immediately.

    00040341
    16.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8457 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple … https://www.cve.org/CVERecord?id=CVE-2026-8457 ----- Traducción: CVE-2026-8457 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-8457, an authentication bypass vulnerability affecting all versions of the WooCommerce – Social Login plugin up to 2.8.7, with a link to the CVE record.

    0000045
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8457 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple … https://www.cve.org/CVERecord?id=CVE-2026-8457

    Post summary

    CVE-2026-8457 identifies an authentication bypass flaw in the WooCommerce Social Login plugin affecting versions up to 2.8.7.

    00000887
    57.9K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-8457: Auth bypass (CVSS 9.8) in WooCommerce Social Login plugin for WordPress (<=2.8.7). Update promptly if using Apple login. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/w3J8iO1QvS

    Post summary

    A critical authentication bypass vulnerability (CVSS 9.8) has been disclosed for the WooCommerce Social Login plugin. Users are urged to update the plugin promptly.

    0000060
    90 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐 CVE-2026-8457 — WooCommerce Social Login Auth Bypass: Apple JWT Forgery (CVSS 9.8) 🔗 https://threataft.com/articles/woocommerce-social-login-auth-bypass-apple-jwt-forgery-cve-2026-8457?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel https://t.co/lXVsIkMsCo

    Post summary

    The tweet announces CVE-2026-8457 for WooCommerce, describing an Apple JWT forgery that bypasses authentication, and cites a CVSS score of 9.8.

    0000060
    36 followersView on X
  • MalwareObserver@MalwareObserver
    General

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-8457](https://codecanyon.net/item/social-login-wordpress-woocommerce-plugin/8495883) Th... https://codecanyon.net/item/social-login-wordpress-woocommerce-plugin/8495883 #CVE #ZeroDay #PatchManagement

    Post summary

    The tweet alerts to CVE-2026-8457 with a link to the affected plugin’s marketplace listing, but offers no further detail, proof of concept, or patch guidance.

    0000049
    18 followersView on X

Explore more