Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-12598— LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth Callback

CVSS 8.1 · High EPSS 0.35% · P27

Affected Version Matrix 1

VendorProductVersion RangeStatus
LoginPressLoginPress Pro≤ 6.2.3affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-12598

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth Callback
Source: CVE Program / CVE List V5
Vulnerability Description
The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me endpoint and using it directly with get_user_by('email', $profile['email']) to identify and log in an existing WordPress account, without confirming that the Spotify user actually owns the email address (Spotify documents that the profile email is unverified) and without requiring the user to prove ownership of the matching WordPress account. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including Administrators, by registering a Spotify account using the targeted user's email address and authenticating via the Spotify provider.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
LoginPress Pro 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
LoginPress LoginPress Pro是LoginPress团队的一款WordPress登录页面定制插件。 LoginPress Pro 6.2.3及之前版本存在授权问题漏洞,该漏洞源于Spotify Social Login插件导致认证绕过,攻击者可通过Spotify登录功能利用未经验证的email字段登录任意WordPress用户账户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LoginPressLoginPress Pro 0 ~ 6.2.3 -

II. Public POCs for CVE-2026-12598

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12598

登录查看更多情报信息。

Vendor Advisories for CVE-2026-12598 (1)

Vendor Pages for CVE-2026-12598 (1)

Same Patch Batch · LoginPress · 2026-07-09 · 3 CVEs total

CVE-2026-125958.1 HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email
CVE-2026-125978.1 HIGHLoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email

IV. Related Vulnerabilities

V. Comments for CVE-2026-12598

No comments yet


Leave a comment