PT-2026-57018 · WordPress · Loginpress Pro
CVE-2026-12598
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LoginPress Pro versions prior to 6.2.4
Description
An authentication bypass exists in the Spotify Social Login addon. The
loginpress on spotify login() function trusts the unverified email field returned by the Spotify /v1/me endpoint and uses it with get user by('email', $profile['email']) to identify and log in a WordPress account. Because the plugin does not confirm that the Spotify user owns the email address or require proof of ownership of the WordPress account, an unauthenticated attacker can log in as any existing user, including Administrators, by creating a Spotify account with the target user's email address.Recommendations
Update to a version newer than 6.2.3.
As a temporary workaround, disable the Spotify Social Login addon.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loginpress Pro