CVE-2026-77001: Social Login & Sharing buttons with Analytics By SoClever <= 1.2.0 - Unauthenticated Authentication Bypass
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obtained without needing to know any account details at all.
Affected Software
Event History
Frequently Asked Questions
Does an attacker need an existing account or any account details to exploit this issue?
No. The affected login handler is publicly accessible and lacks authentication, authorization, and nonce checks. In the default case, an attacker does not need to know any account details.
What level of access can an attacker obtain?
An attacker can obtain a valid session as any existing user, including an administrator. By default, the session obtained is for the site's original administrator account.
Which sites are exposed?
WordPress sites using Social Login & Sharing buttons with Analytics By SoClever version 1.2.0 or earlier are affected.