CVE Database /
CVE-2024-9501
CVE · Critical
CVE-2024-9501 — Wp Social Login and Register Social Counter [wp-social] < 3.0.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-9501
|
Wp Social Login and Register Social Counter [wp-social] < 3.0.8 |
Authentication Bypass Using an Alternate Path or Channel |
Critical
9.8
|
< 3.0.8
|
3.0.8 |
2024-10-25 |
—
|
CVE-2024-9501
A critical security flaw has been identified in the Wp Social Login and Register Social Counter plugin affecting all versions up to 3.0.7. The vulnerability arises from inadequate checks on the identity of users attempting to log in via social media, allowing unauthorized individuals to assume the roles of legitimate account holders, including administrators. Successful exploitation requires only access to a targeted user's email address and their corresponding social media credentials.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings