Authentication Bypass in ZM Ajax Login & Register Plugin for WordPress
CVE-2023-2027
9.8CRITICAL
What is CVE-2023-2027?
The ZM Ajax Login & Register plugin for WordPress, up to version 2.0.2, contains a vulnerability that allows unauthenticated attackers to bypass authentication mechanisms. This occurs due to inadequate verification of user credentials provided during the Facebook login process. Exploiting this flaw, attackers could gain unauthorized access to any existing user account on the site, including those with administrative privileges, provided they know the username.
Affected Version(s)
ZM Ajax Login & Register 0 <= 2.0.2