Executive brief
SmilePass Selfie Login is a WordPress authentication plugin that allows users to log in using selfie verification. The plugin fails to validate login identity on the server side, allowing any unauthenticated attacker to log in as any WordPress account, including administrators, without providing valid credentials or proof of identity.
Technical details
This is an authentication bypass vulnerability (CWE-287) in the SmilePass Selfie Login plugin's login handler. The plugin accepts authentication requests but does not perform any server-side verification of the identity being authenticated, relying solely on client-side checks that can be trivially bypassed. An unauthenticated remote attacker can exploit this by sending a crafted login request for any registered account, including administrators, to gain unauthorized access. The vulnerability requires only network access and no authentication credentials. No fix is currently available as of the advisory date.
Affected products
- SmilePass Selfie Login through 1.0.2
Timeline
- 2026-08-20: disclosed
- 2026-08-22: advisory