WooCommerce Social Login Vulnerable to Authentication Bypass
CVE-2024-10114
8.1HIGH
What is CVE-2024-10114?
The WooCommerce - Social Login plugin for WordPress has a vulnerability that allows unauthorized users to bypass authentication mechanisms present in the plugin. This flaw affects all versions up to and including 2.7.7. The issue arises from inadequate verification of the user associated with the social login token, enabling attackers without credentials to log in as any existing user on the site. If the attacker has knowledge of an existing email and if the corresponding user does not already have an account linked with the social login service, they can gain unauthorized access. This presents a significant security risk, particularly for sites with elevated user privileges.
Affected Version(s)
WooCommerce - Social Login 0 <= 2.7.7