CVE-2024-9106: Wechat Social login <= 1.3.0 - Authentication Bypass
The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9106?
CVE-2024-9106 is considered a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2024-9106?
To fix CVE-2024-9106, upgrade the Wechat Social login plugin for WordPress to version 1.3.1 or later.
What versions are affected by CVE-2024-9106?
CVE-2024-9106 affects all versions of the Wechat Social login plugin for WordPress up to and including 1.3.0.
Can CVE-2024-9106 be exploited remotely?
Yes, CVE-2024-9106 can be exploited remotely by unauthenticated attackers.
What functionality is impacted by CVE-2024-9106?
CVE-2024-9106 allows unauthenticated attackers to bypass authentication and log in using the social login feature.