CVE · High

CVE-2024-10097 — Loginizer [loginizer] < 1.9.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10097 Loginizer [loginizer] < 1.9.3 Improper Authentication High 8.1 < 1.9.3 1.9.3 2024-11-04

CVE-2024-10097

The Loginizer plugin for WordPress through version 1.9.2 contains an authentication bypass vulnerability caused by inadequate validation of user data returned from social login tokens. An unauthenticated attacker who knows a user's email address can gain unauthorized access to that user's account, including administrator accounts, provided the user has not previously linked their account to the social login service. This flaw allows complete account takeover for any site user by exploiting the insufficient token verification mechanism.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.