Authentication vulnerability in Social Share, Social Login and Social Comments Plugin – Super Socializer 7.10.6

The Social Share, Social Login and Social Comments plugin for WordPress has a security weakness that allows unauthenticated attackers to log in as any user, provided they know the user’s email address. This vulnerability exists in versions up to and including 7.10.6 and is caused by a missing capability check on the ‘the_champ_user_auth’ AJAX action.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.