CVE-2023-6036

CRITICAL

Web3 WordPress <3.0.0 - Auth Bypass

Title source: llm

Description

The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

Exploits (1)

nomisec WORKING POC 1 stars
by pctripsesp · poc
https://github.com/pctripsesp/CVE-2023-6036

Scores

CVSS v3 9.8
EPSS 0.5630
EPSS Percentile 98.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (1)
miniorange/web3_-_crypto_wallet_login_\&_nft_token_gating < 3.0.0
Published Feb 12, 2024
Tracked Since Feb 18, 2026