Vulnerability Description
The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.
References
FAQ
What is CVE-2026-77002?
CVE-2026-77002 is a documented vulnerability. The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any reg...
How severe is CVE-2026-77002?
CVSS scoring is not yet available for CVE-2026-77002. Check NVD for updates.
Is there a patch for CVE-2026-77002?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.