First published: Fri May 19 2023(Updated: )
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Social Connect | <=1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2704 has a high severity rating due to the potential for authentication bypass allowing unauthenticated access.
To address CVE-2023-2704, update the BP Social Connect plugin to version 1.6 or later where the vulnerability is resolved.
CVE-2023-2704 affects all users of the BP Social Connect plugin for WordPress versions up to and including 1.5.
CVE-2023-2704 is classified as an authentication bypass vulnerability.
Yes, CVE-2023-2704 can allow unauthenticated attackers to gain unauthorized access to user accounts.