Authentication Bypass Vulnerability in Nextend Social Login Pro by Nextend Web
CVE-2025-1061
9.8CRITICAL
What is CVE-2025-1061?
The Nextend Social Login Pro plugin for WordPress is vulnerable due to inadequate verification on user credentials during Apple OAuth authentication requests. This flaw enables unauthenticated attackers to log in as any existing user, including administrators, if they possess the respective email address. It is essential for users to update to the latest version of the plugin to mitigate this risk and enhance site security.
Affected Version(s)
Nextend Social Login Pro * <= 3.1.16