CVE-2026-8457: WooCommerce Social Login Let Anyone Log In as Admin
CVE-2026-8457 let attackers log in as any admin on WooCommerce sites using Apple login, with no password needed. Here is what happened, how to check if your client sites were exposed, and why disabling unused login providers matters more than patching one at a time.
Read more