PT-2024-37764 · WordPress · Woocommerce - Social Login
Maxntv
+1
·
Published
2024-07-20
·
Updated
2025-02-11
·
CVE-2024-6635
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WooCommerce - Social Login plugin for WordPress versions up to, and including, 2.7.3
Description
The issue is related to authentication bypass due to insufficient controls in the
woo slg login email function. This allows unauthenticated attackers to log in as any existing user on the site, excluding an administrator, if they know the email of the user.Recommendations
For versions up to, and including, 2.7.3, update to a version higher than 2.7.3 to resolve the issue.
As a temporary workaround, consider disabling the
woo slg login email function until a patch is available.Fix
Missing Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Woocommerce - Social Login