PT-2026-79518 · WordPress · Smilepass Selfie Login

·

CVE-2026-77002

·

Published

2026-08-22

·

Updated

2026-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SmilePass Selfie Login versions prior to 1.0.3
Description The SmilePass Selfie Login WordPress plugin fails to perform server-side verification of the identity during the authentication process. This flaw allows unauthenticated users to bypass authentication and log in as any registered account, including those with administrator privileges.
Recommendations Update SmilePass Selfie Login to a version newer than 1.0.2.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77002

Affected Products

Smilepass Selfie Login