Tag

WooCommerce

· Asif Mughal

CVE-2026-8457: WooCommerce Social Login Let Anyone Log In as Admin

CVE-2026-8457 let attackers log in as any admin on WooCommerce sites using Apple login, with no password needed. Here is what happened, how to check if your client sites were exposed, and why disabling unused login providers matters more than patching one at a time.