Executive brief
The Login with NEAR plugin for WordPress, which allows users to sign in using their cryptocurrency wallets, contains a critical security flaw that allows anyone to log in as any user, including administrators. By simply providing a specific account name, an attacker can bypass the entire login process without needing a password or proof of wallet ownership. This could lead to a complete takeover of the website, theft of sensitive data, or unauthorized site modifications.
Technical details
The vulnerability exists in the `ajaxLoginWithNear()` function, which is registered as a `wp_ajax_nopriv` action. The function accepts an attacker-supplied `account` POST parameter and issues a valid WordPress authentication cookie based solely on a substring check for '.near'. It fails to implement any cryptographic signature validation, nonce verification, or challenge-response exchange to prove the requester controls the NEAR wallet. An attacker can log in as any user whose email matches the pattern `<account>@near.org` or trigger the automatic creation of a new authenticated account if no match is found. This is reachable over the network without any prior authentication.
Affected products
- NEAR Protocol Login with NEAR up to, and including, 0.3.3
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory
References
- https://plugins.trac.wordpress.org/browser/near-login/trunk/Controllers/UserLoginController.php
- https://plugins.trac.wordpress.org/browser/near-login/trunk/Controllers/UserLoginController.php
- https://plugins.trac.wordpress.org/browser/near-login/trunk/Controllers/UserLoginController.php
- https://plugins.trac.wordpress.org/browser/near-login/trunk/Controllers/UserLoginController.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f1eacb72-df11-4a3b-9064-f8f776f3522b?source=cve