Privilege Escalation Vulnerability Affects WordPress Social Login and Register
CVE-2023-47683
8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 May 2024
What is CVE-2023-47683?
The improper privilege management vulnerability present in miniOrange's WordPress Social Login and Register plugin allows attackers to exploit the system for privilege escalation. This issue affects users utilizing the plugin across various social platforms, including Discord, Google, Twitter, and LinkedIn, from versions prior to 7.6.6. When exploited, this vulnerability could enable unauthorized access to sensitive functionalities, weakening the overall security posture of affected WordPress installations, and compromising user data and privacy.
Affected Version(s)
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.6