CVE Database /
CVE-2024-9488
CVE · Critical
CVE-2024-9488 — Comments – wpDiscuz [wpdiscuz] < 7.6.25
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-9488
|
Comments – wpDiscuz [wpdiscuz] < 7.6.25 |
Authentication Bypass Using an Alternate Path or Channel |
Critical
9.8
|
< 7.6.25
|
7.6.25 |
2024-10-24 |
—
|
CVE-2024-9488
The wpDiscuz plugin for WordPress, up to version 7.6.24, is susceptible to authentication bypass due to inadequate verification of the user returned by social login tokens. This vulnerability allows unauthenticated attackers to gain access as any existing user, including administrators, if they possess the user's email and can leverage a service that returns the token without proper validation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings