CVE-2024-10097
The Loginizer plugin for WordPress through version 1.9.2 contains an authentication bypass vulnerability caused by inadequate validation of user data returned from social login tokens. An unauthenticated attacker who knows a user's email address can gain unauthorized access to that user's account, including administrator accounts, provided the user has not previously linked their account to the social login service. This flaw allows complete account takeover for any site user by exploiting the insufficient token verification mechanism.
Based on public CVE data (MITRE/NVD).