Authentication vulnerability in Heateor Social Login WordPress 1.1.35

The Heateor Social Login WordPress plugin is currently at risk of being accessed by unauthorized users. This is because the plugin does not properly verify the user who is returning with the social login token. This means that if someone has access to a user’s email and that user does not have an account for the service being used, they can log in as that user on the website. This does not apply to administrator accounts by default, but if the plugin has been set up to allow administrators to use social login, their accounts are also at risk.

Detected in:

Heateor Social Login WordPress fixed vulnerable versions: >= * <= 1.1.35

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.