nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-11015 CVE-2024-11015
CRITICAL
Sign In With Google <= 1.8.0 - Authentication Bypass in authenticate_user
Record summary
CVE-2024-11015 has a selected CVSS score of 9.8 (critical).
Description
The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the 'authenticate_user' user function not implementing sufficient null value checks when setting the access token and user information. This makes it possible for unauthenticated attackers to log in as the first user who has signed in using Google OAuth, which could be the site administrator.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 12, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 12, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Sign In With Google plugin for WordPressBrowse Tanner Record / Sign In With Google plugin for WordPress | VulnCheck | Version data not supplied | |
Sign In With GoogleBrowse tarecord / Sign In With GoogleDefault status: unaffected | CVE List | Through 1.8.0 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/sign-in-with-google/trunk/src/admin/class-sign-in-with-google-admin.php wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/afe894b0-5e91-4aa2-bbd1-1f74274701cf?source=cve