VDB
CVE-2023-2982
CVE-2023-2982
PUBLISHED
CVSS 9.800000190734863 CRITICAL
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the email address associated with that user. This was partially patched in version 7.6.4 and fully patched in version 7.6.5.
EPSS 46.24% · 98.7th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
46.24%
98.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| miniorange | wordpress_social_login_and_register_\(discord\,_google\,_twitter\,_linkedin\) | 0 |
| cyberlord92 | WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) | * |
Timeline
- CVE Published
- Jun 28, 2023 PoC Published
- Jun 29, 2023 EPSS Score
- Jun 29, 2023 VulnCheck XDB Entry
- Jun 30, 2023 VulnCheck XDB Entry
- Jul 7, 2023 VulnCheck XDB Entry
- Nov 18, 2023 VulnCheck XDB Entry
- Dec 8, 2023 PoC Published
- Dec 18, 2023 VulnCheck KEV Exploitation
- Oct 30, 2024 EPSS Score
- Nov 26, 2024 EPSS Score
- Mar 17, 2025 EPSS Score
References
- Nuclei Template exploit
- https://lana.codes/lanavdb/2326f41f-a39f-4fde-8627-9d29fff91443/ url
- https://plugins.trac.wordpress.org/changeset/2924863/miniorange-login-openid vendor
- https://plugins.trac.wordpress.org/changeset/2925914/miniorange-login-openid vendor
- https://www.wordfence.com/threat-intel/vulnerabilities/id/08ca186a-2486-4a58-9c53-03e9eba13e66?source=cve advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-2982 advisory
- https://lana.codes/lanavdb/2326f41f-a39f-4fde-8627-9d29fff91443 url
- https://plugins.trac.wordpress.org/browser/miniorange-login-openid/trunk/mo-openid-social-login-functions.php#L107 url