CVE-2023-24375: WordPress WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 - Broken Access Control vulnerability
Missing Authorization vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register: from n/a through <= 7.5.14.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24375?
CVE-2023-24375 is classified as a Missing Authorization vulnerability which could lead to unauthorized access.
How do I fix CVE-2023-24375?
To mitigate CVE-2023-24375, upgrade the miniOrange WordPress Social Login and Register plugin to version 7.5.15 or later.
What versions are affected by CVE-2023-24375?
CVE-2023-24375 affects versions of miniOrange WordPress Social Login and Register up to and including 7.5.14.
What type of vulnerability is CVE-2023-24375?
CVE-2023-24375 is a Missing Authorization vulnerability that results from incorrectly configured access control security levels.
Can CVE-2023-24375 impact user data?
Yes, CVE-2023-24375 can potentially expose user data due to unauthorized access.