CVE-2023-6036

CRITICAL

Web3 WordPress <3.0.0 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-6036. PoCs published by pctripsesp.

AI-analyzed exploit summary This PoC demonstrates an authentication bypass vulnerability in the Web3 – Crypto wallet Login & NFT token gating WordPress plugin. It exploits incorrect authentication checks in the 'handle_login_request' and 'handle_auth_request' functions to bypass login as an admin user.

Description

The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

Exploits (1)

nomisec WORKING POC 1 stars
by pctripsesp · poc
https://github.com/pctripsesp/CVE-2023-6036

This PoC demonstrates an authentication bypass vulnerability in the Web3 – Crypto wallet Login & NFT token gating WordPress plugin. It exploits incorrect authentication checks in the 'handle_login_request' and 'handle_auth_request' functions to bypass login as an admin user.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Web3 – Crypto wallet Login & NFT token gating < 3.0.0
No auth needed
Prerequisites: Knowledge of a valid username or wallet address
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/7f30ab20-805b-422c-a9a5-21d39c570ee4/

Scores

CVSS v3 9.8
EPSS 0.0177
EPSS Percentile 75.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
miniorange/web3_-_crypto_wallet_login_\&_nft_token_gating < 3.0.0
Published Feb 12, 2024
Tracked Since Feb 18, 2026