28-06-2023 23:01
cve-2023-2982 Vulnerabilidad documentada
9.8 CRITICAL
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for is vulnerable to authentication bypass in versions up to, including, 7.6.4. This due insufficient encryption on the user being supplied during a login validated through plugin. makes it possible unauthenticated attackers log as any existing site, such an administrator, if they know email address associated with that user. was partially patched version 7.6.4 fully 7.6.5.
http://cwe.mitre.org/data/definitions/288.html CWE-288 Authentication Bypass Using Alternate Path or Channel