Unauthorized Data Modification in Wp Social Login and Register Social Counter Plugin for WordPress
CVE-2024-1763
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 March 2024
What is CVE-2024-1763?
The Wp Social Login and Register Social Counter plugin for WordPress has a vulnerability that allows unauthenticated attackers to manipulate data due to a missing capability check on the /wp_social/v1/ REST API endpoint. This flaw affects all versions of the plugin up to and including 3.0.0, enabling attackers to enable or disable configuration settings for social sharing and login features, potentially compromising user experience and security.
Affected Version(s)
Wp Social Login and Register Social Counter 0 <= 3.0.0