PT-2024-15979 · Heateor · Heateor Social Login Wordpress Plugin

Wesley

·

Published

2024-11-05

·

Updated

2024-11-08

·

CVE-2024-10020

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Heateor Social Login WordPress plugin versions up to, and including, 1.1.35
Description The Heateor Social Login WordPress plugin has an authentication bypass issue due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they have access to the email and the user does not have an already-existing account for the service returning the token. An attacker cannot authenticate as an administrator by default, but these accounts are also at risk if authentication for administrators has explicitly been allowed via the social login.
Recommendations Update to the latest version of the Heateor Social Login WordPress plugin to mitigate the risk of unauthorized access. As a temporary workaround, consider restricting access to the social login feature until the update is applied. Avoid using the social login feature for administrator accounts unless absolutely necessary, and ensure that authentication for administrators is not explicitly allowed via the social login.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-10020

Affected Products

Heateor Social Login Wordpress Plugin