CVE-2026-12597
LoginPress LoginPress Pro
The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array returned by GitHub's /user/emails endpoint as an account-binding identifier without verifying that the email carries a verified === true status. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by adding an unverified email addres...
- CVSS
- 8.1
- EPSS
- 0.42% 34.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.10