WooCommerce Social Login Vulnerable to Authentication Bypass
CVE-2024-10114
What is CVE-2024-10114?
The WooCommerce - Social Login plugin for WordPress has a vulnerability that allows unauthorized users to bypass authentication mechanisms present in the plugin. This flaw affects all versions up to and including 2.7.7. The issue arises from inadequate verification of the user associated with the social login token, enabling attackers without credentials to log in as any existing user on the site. If the attacker has knowledge of an existing email and if the corresponding user does not already have an account linked with the social login service, they can gain unauthorized access. This presents a significant security risk, particularly for sites with elevated user privileges.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WooCommerce - Social Login * <= 2.7.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved