Authentications Bypass Vulnerability Affects Wp Social Login and Register Social Counter Plugin
CVE-2024-9501
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 October 2024
What is CVE-2024-9501?
The Wp Social Login and Register Social Counter plugin for WordPress is susceptible to an authentication bypass flaw present in all versions up to 3.0.7. This vulnerability arises from inadequate verification of the user associated with the social login token, enabling unauthenticated attackers to gain access as any existing user on the site. An attacker with knowledge of an existing user's email can exploit this flaw to log in as that user, including those with administrative privileges, provided the victim does not have an existing account with the social service tied to the token. This situation highlights a critical need for enhanced validation processes to protect user accounts from unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Wp Social Login and Register Social Counter * <= 3.0.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved