Description
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an administrator, if they know the email of user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47694 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an administrator, if they know the email of user. |
References
History
Thu, 26 Feb 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpweb
Wpweb woocommerce Social Login |
|
| CPEs | cpe:2.3:a:wpweb:woocommerce_social_login:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wpweb
Wpweb woocommerce Social Login |
|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpwebelite
Wpwebelite woocommerce Social Login |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:wpwebelite:woocommerce_social_login:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpwebelite
Wpwebelite woocommerce Social Login |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:46:23.609Z
Reserved: 2024-07-09T21:27:51.133Z
Link: CVE-2024-6635
Updated: 2024-08-01T21:41:04.272Z
Status : Analyzed
Published: 2024-07-20T08:15:16.177
Modified: 2025-02-11T15:39:13.527
Link: CVE-2024-6635
No data.
OpenCVE Enrichment
No data.
EUVD