Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12597— LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth Callback

Quick assessment

Affected
LoginPress LoginPress Pro
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LoginPress LoginPress Pro是LoginPress团队的一款WordPress登录页面定制插件。 LoginPress Pro 6.2.3及之前版本存在授权问题漏洞,该漏洞源于loginpress_on_github_login()函数未验证电子邮件状态,可能导致未经身份验证的攻击者绕过身份验证并登录为任何现有用户。

CVSS 8.1 · High EPSS 0.57% · P45

Affected Version Matrix 1

VendorProduct Version RangeStatus
LoginPress LoginPress Pro ≤ 6.2.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12597

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth Callback
Source: CVE Program / CVE List V5
Vulnerability Description
The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array returned by GitHub's /user/emails endpoint as an account-binding identifier without verifying that the email carries a verified === true status. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by adding an unverified email address matching a local account to their GitHub profile and triggering the OAuth callback via a crafted code parameter — causing the plugin to call get_user_by('email', ...) and establish an authenticated session for the matched account. Practical exploitation is conditional on GitHub returning the attacker-added unverified email at index 0 of the /user/emails response, as GitHub typically prioritizes the primary verified address first; nonetheless, the absence of any email verification check in the plugin constitutes a fundamental authentication bypass flaw.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
LoginPress Pro 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
LoginPress LoginPress Pro是LoginPress团队的一款WordPress登录页面定制插件。 LoginPress Pro 6.2.3及之前版本存在授权问题漏洞,该漏洞源于loginpress_on_github_login()函数未验证电子邮件状态,可能导致未经身份验证的攻击者绕过身份验证并登录为任何现有用户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
LoginPress LoginPress Pro 0 ~ 6.2.3 -

II. Public POCs for CVE-2026-12597

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12597

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-12597 (1)

Vendor Pages for CVE-2026-12597 (1)

Same Patch Batch · LoginPress · 2026-07-09 · 3 CVEs total

CVE-2026-12595 8.1 HIGH LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email
CVE-2026-12598 8.1 HIGH LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email

IV. Related Vulnerabilities

V. Comments for CVE-2026-12597

No comments yet


Leave a comment