CVE-2024-4544: Pie Register - Social Sites Login (Add on) <= 1.7.7 - Authentication Bypass
The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.7. This is due to insufficient verification on the user being supplied during a social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Pie Register - Social Sites Login (Add on)to a version that resolves this vulnerability.Fixed in 1.7.7
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4544?
The severity of CVE-2024-4544 is considered high due to the risk of authentication bypass.
How do I fix CVE-2024-4544?
To fix CVE-2024-4544, update the Pie Register - Social Sites Login plugin to version 1.7.8 or later.
What systems are affected by CVE-2024-4544?
CVE-2024-4544 affects versions of the Pie Register - Social Sites Login plugin for WordPress up to and including 1.7.7.
What type of vulnerability is CVE-2024-4544?
CVE-2024-4544 is classified as an authentication bypass vulnerability.
Is CVE-2024-4544 easy to exploit?
Yes, CVE-2024-4544 is relatively easy to exploit due to insufficient verification during social login.