CVE-2024-6637
—CVSS 3.1
7.3 high
EPSS
<1%p30
Published
()
Modified
Description
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for any user, except an Administrator, if they know the email of user.
- Vendors
- wpwebelite
- Products
- woocommerce social login
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-305
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.