Junglewise Threat Intelligence

CVE-2026-8994: Login with NEAR WordPress plugin authentication bypass

CVE-2026-8994 · Severity: high · CVSS 8.1 · Published 2026-05-27

Executive brief

The Login with NEAR plugin for WordPress, which allows users to sign in using their cryptocurrency wallets, contains a critical security flaw that allows anyone to log in as any user, including administrators. By simply providing a specific account name, an attacker can bypass the entire login process without needing a password or proof of wallet ownership. This could lead to a complete takeover of the website, theft of sensitive data, or unauthorized site modifications.

Technical details

The vulnerability exists in the `ajaxLoginWithNear()` function, which is registered as a `wp_ajax_nopriv` action. The function accepts an attacker-supplied `account` POST parameter and issues a valid WordPress authentication cookie based solely on a substring check for '.near'. It fails to implement any cryptographic signature validation, nonce verification, or challenge-response exchange to prove the requester controls the NEAR wallet. An attacker can log in as any user whose email matches the pattern `<account>@near.org` or trigger the automatic creation of a new authenticated account if no match is found. This is reachable over the network without any prior authentication.

Affected products

  • NEAR Protocol Login with NEAR up to, and including, 0.3.3

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References