The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the userID. This requires the email module to be enabled.
History

Fri, 07 Feb 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Wpwebelite
Wpwebelite woocommerce Social Login
Weaknesses CWE-306
CPEs cpe:2.3:a:wpwebelite:woocommerce_social_login:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpwebelite
Wpwebelite woocommerce Social Login

Tue, 13 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Wpweb
Wpweb woocommerce Social Login
CPEs cpe:2.3:a:wpweb:woocommerce_social_login:*:*:*:*:*:*:*:*
Vendors & Products Wpweb
Wpweb woocommerce Social Login
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 10 Aug 2024 02:30:00 +0000

Type Values Removed Values Added
Description The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the userID. This requires the email module to be enabled.
Title WooCommerce - Social Login <= 2.7.5 - Authentication Bypass to Account Takeover
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-13T15:18:37.863Z

Reserved: 2024-08-05T17:25:54.172Z

Link: CVE-2024-7503

cve-icon Vulnrichment

Updated: 2024-08-13T15:18:31.374Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-12T13:38:43.357

Modified: 2025-02-07T16:06:13.577

Link: CVE-2024-7503

cve-icon Redhat

No data.