Description
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for any user, except an Administrator, if they know the email of user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47696 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for any user, except an Administrator, if they know the email of user. |
References
History
Wed, 08 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yithemes
Yithemes yith Woocommerce Social Login |
|
| CPEs | cpe:2.3:a:yithemes:yith_woocommerce_social_login:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Yithemes
Yithemes yith Woocommerce Social Login |
|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpwebelite
Wpwebelite woocommerce Social Login |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:wpwebelite:woocommerce_social_login:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpwebelite
Wpwebelite woocommerce Social Login |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:36:07.667Z
Reserved: 2024-07-09T21:48:55.671Z
Link: CVE-2024-6637
Updated: 2024-08-01T21:41:04.300Z
Status : Analyzed
Published: 2024-07-20T08:15:16.840
Modified: 2025-02-11T15:43:25.850
Link: CVE-2024-6637
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD