Overview
- Description
- The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they have access to the email and the user does not have an already-existing account for the service returning the token. An attacker cannot authenticate as an administrator by default, but these accounts are also at risk if authentication for administrators has explicitly been allowed via the social login.
- Source
- security@wordfence.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
- security@wordfence.com
- CWE-287
Social media
- Hype score
- Not currently trending
🚨 CVE-2024-10020 (Published: 2024-11-06) - A critical vulnerability in Heateor plugin affects multiple WordPress versions. Users are urged to update to the latest version immediately to mitigate risks. Stay secure! 🔒 For details: https://t.co/LAXb5yfzrR #WordPress… https://t.co
@transilienceai
7 Nov 2024
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2024-10020 (Published: 2024-11-06) - Critical vulnerability in Heateor plugin for WordPress. Affects multiple versions. Remediation: Update to the latest version immediately to secure your site. Stay safe! 🔒 More info: https://t.co/LAXb5yfzrR #WordPress #Security
@transilienceai
7 Nov 2024
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-10020 The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficie… https://t.co/H3I4Nh1YDC
@CVEnew
6 Nov 2024
674 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:heateor:social_login:*:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "9248BE1D-7546-4B2D-884F-96A7C6950E5E", "versionEndExcluding": "1.1.36" } ], "operator": "OR" } ] } ]