CVE-2024-9106

CRITICAL

Wechat Social login plugin <1.3.0 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-9106. PoCs published by RandomRobbieBF.

AI-analyzed exploit summary The PoC demonstrates an authentication bypass vulnerability in the Wechat Social Login WordPress plugin (versions <= 1.3.0) by manipulating the `uid` parameter to log in as any user. The exploit requires the app secret to be unset (default empty value) and leverages insufficient verification during social login.

Description

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.

Exploits (1)

nomisec WORKING POC 1 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-9106

The PoC demonstrates an authentication bypass vulnerability in the Wechat Social Login WordPress plugin (versions <= 1.3.0) by manipulating the `uid` parameter to log in as any user. The exploit requires the app secret to be unset (default empty value) and leverages insufficient verification during social login.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Wechat Social Login WordPress plugin <= 1.3.0
No auth needed
Prerequisites: App secret must be unset (default empty value) · Knowledge of target user ID
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0166
EPSS Percentile 73.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-288
Status published
Products (1)
xunhuweb/Wechat Social login 微信QQ钉钉登录插件 < 1.3.0
Published Oct 01, 2024
Tracked Since Feb 18, 2026