NONE · 0

CVE-2026-77001

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login ...

Vulnerability Description

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obtained without needing to know any account details at all.

References

FAQ

What is CVE-2026-77001?

CVE-2026-77001 is a documented vulnerability. The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login ...

How severe is CVE-2026-77001?

CVSS scoring is not yet available for CVE-2026-77001. Check NVD for updates.

Is there a patch for CVE-2026-77001?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.