Authentication vulnerability in Wp Social Login and Register Social Counter 3.0.7

The Wp Social Login and Register Social Counter plugin for WordPress has a security issue that allows unauthorized access to user accounts. This happens because the plugin does not properly check the user’s identity when they use a social login token. As a result, attackers without an account can log in as any existing user on the site, including administrators, if they know the user’s email and the service used for the login.

Detected in:

Wp Social Login and Register Social Counter fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.