The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.
History

Fri, 07 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wpwebelite
Wpwebelite woocommerce Social Login
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:wpwebelite:woocommerce_social_login:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpwebelite
Wpwebelite woocommerce Social Login

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T21:25:02.989Z

Reserved: 2024-06-11T15:31:25.064Z

Link: CVE-2024-5868

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:02.989Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-15T04:15:13.373

Modified: 2025-02-07T19:49:25.727

Link: CVE-2024-5868

cve-icon Redhat

No data.