WooCommerce - Social Login <= 2.7.5 - Authentication Bypass to Account Takeover
CVE-2024-7503
What is CVE-2024-7503?
The WooCommerce - Social Login plugin for WordPress is susceptible to an authentication bypass vulnerability. This flaw arises from the improper comparison of the activation code within the 'woo_slg_confirm_email_user' function, which can be exploited by unauthenticated attackers. If they possess the userID, attackers may gain the ability to log in as any existing user, including administrators, provided that the email module is enabled. This vulnerability underscores the importance of maintaining updated versions and rigorous security practices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WooCommerce - Social Login * <= 2.7.5
References
CVSS V3.1
Timeline
Vulnerability published