The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an administrator, if they know the email of user.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47694 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an administrator, if they know the email of user. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Feb 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpweb
Wpweb woocommerce Social Login |
|
| CPEs | cpe:2.3:a:wpweb:woocommerce_social_login:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wpweb
Wpweb woocommerce Social Login |
|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpwebelite
Wpwebelite woocommerce Social Login |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:wpwebelite:woocommerce_social_login:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpwebelite
Wpwebelite woocommerce Social Login |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T21:41:04.272Z
Reserved: 2024-07-09T21:27:51.133Z
Link: CVE-2024-6635
Updated: 2024-08-01T21:41:04.272Z
Status : Analyzed
Published: 2024-07-20T08:15:16.177
Modified: 2025-02-11T15:39:13.527
Link: CVE-2024-6635
No data.
OpenCVE Enrichment
No data.
EUVD