CVE-2024-37502: WordPress Social Login plugin <= 2.6.3 - PHP Object Injection vulnerability
Published Jul 9, 2024
·Updated
Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3.
Affected Software
3 affected components
wpweb WooCommerce Social Login<=2.6.3
WordPress Social Login<=2.6.3
Wpwebelite Woocommerce Social Login Wordpress<2.7.0
Remediation
Information
Update to 2.7.0 or a higher version.
Event History
Jul 9, 2024
CVE Published
via MITRE·08:57 AM
Data Sourced
via MITRE·08:57 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37502?
CVE-2024-37502 has been classified as a critical severity vulnerability due to its potential impact on system security.
2
How do I fix CVE-2024-37502?
To remediate CVE-2024-37502, update WooCommerce Social Login to version 2.6.4 or later.
3
What systems are affected by CVE-2024-37502?
CVE-2024-37502 affects WooCommerce Social Login versions up to and including 2.6.3.
4
What type of vulnerability is CVE-2024-37502?
CVE-2024-37502 is a deserialization of untrusted data vulnerability.
5
Is CVE-2024-37502 exploitable remotely?
Yes, CVE-2024-37502 is exploitable remotely, allowing attackers to manipulate sensitive data.