PT-2026-79516 · WordPress · Wp Social Media Login
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Social Media Login versions prior to 1.0.7
Description
The WP Social Media Login WordPress plugin fails to verify if a social login process was successfully completed with the identity provider before authenticating a visitor. This allows unauthenticated attackers to gain access to any existing user account, including those with administrator privileges, by providing the target user's email address.
Recommendations
Update WP Social Media Login to version 1.0.7 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Social Media Login