August 2026 — Web Design & Dev news.
What changed, as it happens.
Tracked daily from primary sources. The items below are what we're watching for clients right now.
A forged Apple login token takes over any WordPress site running WooCommerce Social Login
CVE-2026-8457 is a critical authentication-bypass vulnerability in the WooCommerce Social Login plugin, affecting versions up to and including 2.8.7 and fixed in 2.8.8. It scores 9.8 out of 10 on CVSS. The plugin's Apple login handler does not validate Apple's JWT identity tokens against Apple's public keys, so an attacker can forge a token carrying any email address and be signed in as the matching user. Wordfence describes the result as unauthenticated attackers being able to log in as any existing WordPress user, including administrators. Administrator accounts carry no exclusion protection here, so a successful attempt hands over full control of the site without any legitimate credentials.Source: Search Engine Journal →
Our take: Update to 2.8.8 today if this plugin is installed anywhere you touch. A 9.8 with a forged-token path and no credentials required is the class that gets scanned for within days of disclosure, and social login is the kind of plugin switched on once during a launch and never opened again. For most BigCommerce and Shopify merchants the exposure sits on the WordPress blog or landing-page install on a subdomain beside the store, where the plugin list has not been read in a year and an administrator account is one forged token away.
Read our full take →
Custom ecommerce software, AI apps, and SEO — the work other agencies quote around, built in-house.
20+ years of BigCommerce engineering, now AI-augmented. Tell us your store, your stack, and your deadline — we quote fixed scope on the first call.