Impact
An unauthenticated broken authentication flaw exists in versions of Super Socializer up to 7.14.5, allowing an attacker to bypass normal login controls and obtain full administrative privileges. This vulnerability falls under the CWE-288 category and could lead to compromise of the entire WordPress site, including content, user data, and configuration settings. The potential impact includes data theft, site defacement, and further lateral movement within the hosting environment.
Affected Systems
The affected product is Super Socializer, developed by Rajat Varlani, a WordPress plugin used for social login and sharing features. All releases from the first version through 7.14.5 are vulnerable. Users running any of these versions should verify the installed version number and consider an immediate update.
Risk and Exploitability
With a CVSS score of 8.8, this vulnerability is classified as high severity. EPSS information is not available, so the exploitation probability cannot be quantified; however, the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote exploitation via web requests to the plugin's authentication endpoints, as the flaw allows unauthenticated access. An attacker would need only network access to the WordPress site to leverage the flaw, making it broadly exploitable.
OpenCVE Enrichment