CVE-2024-6635: WooCommerce - Social Login <= 2.7.3 - Unauthenticated Authentication Bypass
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'wooslgloginemail' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an administrator, if they know the email of user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6635?
The severity of CVE-2024-6635 is considered critical due to the potential for authentication bypass.
How do I fix CVE-2024-6635?
To fix CVE-2024-6635, update the WooCommerce - Social Login plugin to version 2.7.4 or later.
What versions are affected by CVE-2024-6635?
CVE-2024-6635 affects WooCommerce - Social Login plugin versions up to and including 2.7.3.
Who can exploit CVE-2024-6635?
CVE-2024-6635 can be exploited by unauthenticated attackers who can bypass authentication.
What is the impact of CVE-2024-6635?
The impact of CVE-2024-6635 allows attackers to log in as any existing user without authentication.