Authentication Bypass in Nextend Social Login Pro for WordPress
CVE-2024-9893
What is CVE-2024-9893?
The Nextend Social Login Pro plugin for WordPress presents a security vulnerability due to inadequate verification of users authenticated through social login tokens. This flaw allows unauthenticated attackers to gain unauthorized access by impersonating any existing user on the site. Specifically, if an attacker knows the email address of a user and the user does not have a pre-existing account linked to the social service providing the token, the attacker can log in as that user, including administrators. This vulnerability raises significant concerns regarding site integrity and user data protection.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Nextend Social Login Pro * <= 3.1.14
References
CVSS V3.1
Timeline
Vulnerability published