PT-2026-67101 · WordPress · Social Login
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
login-social WordPress plugin versions prior to 1.0.5
Description
This issue occurs because the plugin fails to validate password-reset requests against a reset key or the identity of the requester. Additionally, it generates authentication sessions based on unverified third-party sign-in data. This allows unauthenticated attackers to reset passwords for any user or log in as any existing account, including those with administrator privileges, leading to full site takeover.
Recommendations
Update the login-social WordPress plugin to version 1.0.5 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Social Login