Unauthenticated Access to Site Users Through Social Login Bypass
Key Information
- Vendor
- Xunhuweb
- Status
- Wechat Social Login 微信qq钉钉登录插件
- Vendor
- CVE Published:
- 1 October 2024
Badges
Summary
The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.
Affected Version(s)
Wechat Social login 微信QQ钉钉登录插件 <= 1.3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
CVSS V3.1
Timeline
- 👾
Exploit exists.
Vulnerability published.
Disclosed
Vulnerability Reserved.
Discovered
Vendor Notified