Authentication vulnerability in Sign In With Google 1.8.0

The plugin used to sign in with Google on WordPress has a security issue in all versions up to 1.8.0. This is because the function that verifies the user does not check for empty values when setting the access token and user information. As a result, hackers who are not logged in can access the account of the first user who used Google OAuth to sign in, potentially giving them control over the entire website.

Detected in:

Sign In With Google open vulnerable versions: >= * <= 1.8.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.