CVE-2024-1763: Wp Social Login and Register Social Counter <= 3.0.0 - Missing Authorization to Unauthenticated Social Login/Share Status Update
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wpsocial/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable certain providers for the social share and login features.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1763?
CVE-2024-1763 has a medium severity rating due to unauthorized modification of data.
How do I fix CVE-2024-1763?
To fix CVE-2024-1763, update the Wp Social Login and Register Social Counter plugin to version 3.0.1 or higher.
Who is affected by CVE-2024-1763?
Anyone using the Wp Social Login and Register Social Counter plugin for WordPress version 3.0.0 or lower is affected by CVE-2024-1763.
What could an attacker do with CVE-2024-1763?
An attacker could exploit CVE-2024-1763 to perform unauthorized changes to data through the vulnerable REST API endpoint.
Is my site secure if I update to the latest version of the plugin regarding CVE-2024-1763?
Yes, updating to the latest version of the Wp Social Login and Register Social Counter plugin effectively mitigates the risks associated with CVE-2024-1763.