WooCommerce - Social Login <= 2.7.5 - Authentication Bypass to Account Takeover
CVE-2024-7503
9.8CRITICAL
What is CVE-2024-7503?
The WooCommerce - Social Login plugin for WordPress is susceptible to an authentication bypass vulnerability. This flaw arises from the improper comparison of the activation code within the 'woo_slg_confirm_email_user' function, which can be exploited by unauthenticated attackers. If they possess the userID, attackers may gain the ability to log in as any existing user, including administrators, provided that the email module is enabled. This vulnerability underscores the importance of maintaining updated versions and rigorous security practices.
Affected Version(s)
WooCommerce - Social Login 0 <= 2.7.5