WooCommerce Social Login Vulnerable to Authentication Bypass
CVE-2024-10114

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 November 2024

What is CVE-2024-10114?

The WooCommerce - Social Login plugin for WordPress has a vulnerability that allows unauthorized users to bypass authentication mechanisms present in the plugin. This flaw affects all versions up to and including 2.7.7. The issue arises from inadequate verification of the user associated with the social login token, enabling attackers without credentials to log in as any existing user on the site. If the attacker has knowledge of an existing email and if the corresponding user does not already have an account linked with the social login service, they can gain unauthorized access. This presents a significant security risk, particularly for sites with elevated user privileges.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WooCommerce - Social Login * <= 2.7.7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wesley
.