Authentication vulnerability in Web3 – Crypto wallet Login & NFT token gating 2.8.0

A plugin for WordPress, called Web3, which helps with login and managing virtual tokens, has a security issue. This problem affects all versions up to 2.8.0. The issue is that the plugin does not properly check for authorization when handling authentication and login requests. This means that someone who is not logged in can pretend to be any user, even an administrator, as long as they know the username.

Detected in:

Web3 – Crypto wallet Login & NFT token gating fixed vulnerable versions: >= * <= 2.8.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.