PT-2026-57018 · WordPress · Loginpress Pro

CVE-2026-12598

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LoginPress Pro versions prior to 6.2.4
Description An authentication bypass exists in the Spotify Social Login addon. The loginpress on spotify login() function trusts the unverified email field returned by the Spotify /v1/me endpoint and uses it with get user by('email', $profile['email']) to identify and log in a WordPress account. Because the plugin does not confirm that the Spotify user owns the email address or require proof of ownership of the WordPress account, an unauthenticated attacker can log in as any existing user, including Administrators, by creating a Spotify account with the target user's email address.
Recommendations Update to a version newer than 6.2.3. As a temporary workaround, disable the Spotify Social Login addon.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12598

Affected Products

Loginpress Pro