CVE · Critical

CVE-2024-9501 — Wp Social Login and Register Social Counter [wp-social] < 3.0.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-9501 Wp Social Login and Register Social Counter [wp-social] < 3.0.8 Authentication Bypass Using an Alternate Path or Channel Critical 9.8 < 3.0.8 3.0.8 2024-10-25

CVE-2024-9501

A critical security flaw has been identified in the Wp Social Login and Register Social Counter plugin affecting all versions up to 3.0.7. The vulnerability arises from inadequate checks on the identity of users attempting to log in via social media, allowing unauthorized individuals to assume the roles of legitimate account holders, including administrators. Successful exploitation requires only access to a targeted user's email address and their corresponding social media credentials.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.