CVE-2026-77002

Summary

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

Affected Software

VendorProductVersion RangeStatus
UnknownSmilePass Selfie Login0 <= 1.0.2affected

Weaknesses

  • CWE-287 Improper Authentication

References