CVE · Medium

CVE-2024-1763 — Wp Social Login and Register Social Counter [wp-social] < 3.0.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1763 Wp Social Login and Register Social Counter [wp-social] < 3.0.1 Missing Authorization Medium 5.3 < 3.0.1 3.0.1 2024-02-29

CVE-2024-1763

The Wp Social Login and Register Social Counter plugin through version 3.0.0 contains a broken access control vulnerability that allows unauthenticated or low-privileged users to perform actions normally restricted to higher-privileged users due to missing authorization and nonce checks. The flaw was discovered by Krzysztof Zając and has been resolved in version 3.0.1, which users should upgrade to immediately.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.