wpweb Vulnerabilities and Affected Products
Vulnerabilities associated with WooCommerce - Social Login.
Products
Clear product- Social Auto Poster9 vulnerabilities
- WooCommerce - Social Login8 vulnerabilities
- woocommerce_social_login6 vulnerabilities
- social_auto_poster3 vulnerabilities
- WooCommerce PDF Vouchers3 vulnerabilities
- woocommerce_pdf_vouchers3 vulnerabilities
- Follow My Blog Post2 vulnerabilities
- WooCommerce Social Login2 vulnerabilities
- Docket (WooCommerce Collections / Wishlist / Watchlist)1 vulnerability
- WooCommerce - PDF Vouchers1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-8457CRITICAL | WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWTThe WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or validating the issuer, audience, or expiry claims, combined with the security nonce required to invoke the login flow being publicly exposed to unauthenticated users via a localized Jav… CWE-289Aug 1, 2026 | CVSS9.8v3.1 | EPSS0.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10114HIGH | Social Login - WordPress / WooCommerce Plugin <= 2.7.7 - Authentication Bypass via WordPress.com OAuth providerThe WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token. CWE-287Nov 5, 2024 | CVSS8.1v3.1 | EPSS0.539% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7503CRITICAL | WooCommerce - Social Login <= 2.7.5 - Authentication Bypass to Account TakeoverThe WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the userID. This requires the email module to be enabled. | CVSS9.8v3.1 | EPSS0.61% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6636CRITICAL | WooCommerce - Social Login <= 2.7.3 - Missing Authorization to Unauthenticated Privilege EscalationThe WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator while registering for an account. CWE-862Jul 20, 2024 | CVSS9.8v3.1 | EPSS0.518% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6635HIGH | WooCommerce - Social Login <= 2.7.3 - Unauthenticated Authentication BypassThe WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an administrator, if they know the email of user. | CVSS7.3v3.1 | EPSS0.403% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6637HIGH | WooCommerce - Social Login <= 2.7.3 - Unauthenticated Privilege Escalation via One-Time PasswordThe WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for any user, except an Administrator, if they know the email of user. CWE-305Jul 20, 2024 | CVSS7.3v3.1 | EPSS0.362% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5871CRITICAL | WooCommerce - Social Login <= 2.6.2 - Unauthenticated PHP Object InjectionThe WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary file… CWE-502Jun 15, 2024 | CVSS9.8v3.1 | EPSS0.697% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5868MEDIUM | WooCommerce - Social Login <= 2.6.2 - Email Verification due to Insufficient RandomnessThe WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification. CWE-330Jun 15, 2024 | CVSS6.5v3.1 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |