Authentication vulnerability in Login with Cognito 1.4.6

The Login with Cognito plugin for WordPress is a tool that helps people log in to their WordPress sites. Unfortunately, versions of the plugin up to and including 1.4.6 have a security flaw that makes it possible for unauthenticated attackers to log in as a site administrator, without needing a password. This is because the plugin doesn’t check if the email address provided when logging in actually belongs to the person trying to access the site. As long as the attacker has access to an administrator’s email address, they can log in.

Detected in:

Login with Cognito fixed vulnerable versions: >= * <= 1.4.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.