CVE-2023-2704: BP Social Connect <= 1.5 - Authentication Bypass
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2704?
CVE-2023-2704 has a high severity rating due to the potential for authentication bypass allowing unauthenticated access.
How do I fix CVE-2023-2704?
To address CVE-2023-2704, update the BP Social Connect plugin to version 1.6 or later where the vulnerability is resolved.
Who is affected by CVE-2023-2704?
CVE-2023-2704 affects all users of the BP Social Connect plugin for WordPress versions up to and including 1.5.
What type of vulnerability is CVE-2023-2704?
CVE-2023-2704 is classified as an authentication bypass vulnerability.
Can CVE-2023-2704 lead to unauthorized access?
Yes, CVE-2023-2704 can allow unauthenticated attackers to gain unauthorized access to user accounts.