Authenticated Logins Are Now a Thing of the Past
CVE-2024-9488

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 October 2024

What is CVE-2024-9488?

The wpDiscuz plugin for WordPress has a vulnerability that allows attackers to bypass authentication mechanisms. This issue arises from inadequate verification of the user linked to the social login token, affecting versions up to and including 7.6.24. As a result, unauthenticated attackers could gain login privileges as any existing user, including administrators, provided they know the email associated with the targeted account and that no corresponding user account exists for the service that returns the social login token. This flaw significantly increases the risk of unauthorized access and potential exploitation of user privileges on WordPress sites.

Affected Version(s)

Comments – wpDiscuz * <= 7.6.24

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wesley
.