Authentication vulnerability in WooCommerce – Social Login 2.7.7

The plugin called “WooCommerce – Social Login” for WordPress has a security flaw that allows unauthorized people to log in as any user on the website, including administrators. This is because the plugin does not properly check the user’s information from the social media login. Attackers without an account on the site can use this loophole if they know the user’s email and the social media service.

Detected in:

WooCommerce - Social Login fixed vulnerable versions: >= * <= 2.7.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.