Authentication vulnerability in Wechat Social login 微信QQ钉钉登录插件 1.3.0

The Wechat Social login plugin for WordPress has a security flaw that allows unauthorized users to log in as any existing user on the site, including administrators. This is because the plugin does not properly verify the user’s identity during the social login process. This vulnerability can only be exploited if the app secret is not set, which is often left as an empty value by default.

Detected in:

Wechat Social login 微信QQ钉钉登录插件 open vulnerable versions: >= * <= 1.3.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.