NONE · 0

CVE-2026-77002

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any reg...

Vulnerability Description

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

References

FAQ

What is CVE-2026-77002?

CVE-2026-77002 is a documented vulnerability. The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any reg...

How severe is CVE-2026-77002?

CVSS scoring is not yet available for CVE-2026-77002. Check NVD for updates.

Is there a patch for CVE-2026-77002?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.