CVE-2023-2982
CRITICAL EXPLOITED NUCLEIMiniorange Wordpress Social Login And... - Authentication Bypass
Title source: ruleDescription
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the email address associated with that user. This was partially patched in version 7.6.4 and fully patched in version 7.6.5.
Exploits (4)
nomisec
WORKING POC
82 stars
by RandomRobbieBF · remote
https://github.com/RandomRobbieBF/CVE-2023-2982
Nuclei Templates (1)
Miniorange Social Login and Register <= 7.6.3 - Authentication Bypass
CRITICALVERIFIEDby ritikchaddha
References (5)
Scores
CVSS v3
9.8
EPSS
0.7012
EPSS Percentile
98.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2023-12-18
Classification
Status
published
Affected Products (1)
miniorange/wordpress_social_login_and_register_\(discord\,_google\,_twitter\,_linkedin\)
< 7.6.5
Timeline
Published
Jun 29, 2023
Tracked Since
Feb 18, 2026