ZeroHour

CVE-2024-5868

CVSS 3.1
5.3 medium
EPSS
<1%p24
Published
()
Modified
Description

The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.

Vendors
wpwebelite
Products
woocommerce social login
Ecosystems
WordPress, E-commerce
Weakness
CWE-330
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.