← Back to CVE List

CVE-2024-6637

Published: 2024-07-20T08:15Z
Last Modified: 2025-02-11T15:43Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for any user, except an Administrator, if they know the email of user. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt