CVE-2024-9106

CRITICAL

Wechat Social login plugin <1.3.0 - Auth Bypass

Title source: llm

Description

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.

Exploits (1)

nomisec WORKING POC 1 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-9106

Scores

CVSS v3 9.8
EPSS 0.4118
EPSS Percentile 97.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-288
Status published
Products (1)
xunhuweb/Wechat Social login 微信QQ钉钉登录插件 < 1.3.0
Published Oct 01, 2024
Tracked Since Feb 18, 2026