← Back to CVE List

CVE-2024-6635

Published: 2024-07-20T08:15Z
Last Modified: 2025-02-11T15:39Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an administrator, if they know the email of user. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt