WooCommerce Social Login CVE-2026-8457: Patch or Pause Checklist
August 1, 2026
WooCommerce Social Login CVE-2026-8457: Patch or Pause Checklist
Priority: The official CVE record identifies an authentication-bypass vulnerability in the commercial WPWeb WooCommerce – Social Login plugin in versions through 2.8.7. Affected sites can face unauthorized access to existing WordPress accounts. This is not a WooCommerce core issue, and it is not the separate miniOrange Social Login plugin.
The record was published on August 1, 2026. WPWeb’s product changelog now lists version 2.8.8, dated July 27, 2026, with improved validation and verification of Apple Sign-In ID tokens. Update affected sites to version 2.8.8 or later after confirming the package comes from the vendor’s release channel. Fix I.T. Phill has not confirmed active exploitation, and this is not a WooCommerce core issue.
Who needs to act
- WordPress or WooCommerce sites using WPWeb’s commercial WooCommerce – Social Login plugin through version 2.8.7.
- Stores with social sign-in enabled for shoppers, staff, editors, or administrators.
- Agencies and hosts that manage multiple WordPress sites and need to distinguish this product from similarly named social-login plugins.
Immediate checklist
- Identify whether the affected WPWeb plugin is installed and record its version before making changes.
- Confirm the installed plugin is WPWeb’s WooCommerce – Social Login and compare its version with the vendor’s 2.8.8 release note.
- Update affected sites to version 2.8.8 or later during a controlled maintenance window, then test ordinary customer sign-in, account access, checkout, payment return, and order email workflows.
- If the update cannot be completed promptly, temporarily remove the Apple social-login choice from the live login experience. If that cannot be done cleanly, disable the affected plugin until the update is verified.
- Review recent account and authentication activity for unfamiliar privileged access, unexpected account changes, or new administrative users. Escalate suspicious findings through your normal incident-response process.
- Ask a responsible site administrator to invalidate active sessions for sensitive accounts when there is a credible concern that an account was accessed without authorization.
After the change
Confirm that the store’s normal login, password reset, account, checkout, payment, email, and order-management flows still work. Keep a brief record of the version decision, change window, and verification result. For a broader maintenance sequence, use the WordPress Support Guide, the WooCommerce update checklist, and the WordPress security-alert review guide.
What remains unconfirmed
The official CVE record confirms the affected product and versions through 2.8.7. The record itself does not name a fixed release, but WPWeb’s version 2.8.8 changelog documents an Apple Sign-In token-validation and verification fix. Treat 2.8.8 as the vendor’s remediation release, while continuing to watch for an updated CVE record, CISA KEV entry, or independently confirmed active exploitation.

