Authenticated Logins Are Now a Thing of the Past
CVE-2024-9488
What is CVE-2024-9488?
The wpDiscuz plugin for WordPress has a vulnerability that allows attackers to bypass authentication mechanisms. This issue arises from inadequate verification of the user linked to the social login token, affecting versions up to and including 7.6.24. As a result, unauthenticated attackers could gain login privileges as any existing user, including administrators, provided they know the email associated with the targeted account and that no corresponding user account exists for the service that returns the social login token. This flaw significantly increases the risk of unauthorized access and potential exploitation of user privileges on WordPress sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Comments β wpDiscuz * <= 7.6.24
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved