Extension WordPress
Vulnérabilités WooCommerce – Social Login
Cette page rassemble les failles publiées pour WooCommerce – Social Login, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WooCommerce – Social Login
9 fiches
WooCommerce Social Login <= 2.8.2 – Cross-Site Request Forgery
The WooCommerce – Social Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.2. This is due to missing or incorrect nonce validation on a function. This makes it possible…
*-2.8.2
2.8.3
16/04/2025
Social Login – WordPress / WooCommerce Plugin <= 2.7.7 – Authentication Bypass via WordPress.com OAuth provider
The WooCommerce – Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This…
*-2.7.7
2.7.8
04/11/2024
WooCommerce – Social Login <= 2.7.5 – Authentication Bypass to Account Takeover
The WooCommerce – Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This…
*-2.7.5
2.7.6
09/08/2024
WooCommerce – Social Login <= 2.7.3 – Missing Authorization to Unauthenticated Privilege Escalation
The WooCommerce – Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for…
*-2.7.3
2.7.4
19/07/2024
WooCommerce – Social Login <= 2.7.3 – Unauthenticated Authentication Bypass
The WooCommerce – Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to…
*-2.7.3
2.7.4
19/07/2024
WooCommerce – Social Login <= 2.7.3 – Unauthenticated Privilege Escalation via One-Time Password
The WooCommerce – Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This…
*-2.7.3
2.7.4
19/07/2024
WooCommerce Social Login <= 2.6.3 – Unauthenticated PHP Object Injection
The WooCommerce – Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP…
*-2.6.3
2.7.0
05/07/2024
WooCommerce – Social Login <= 2.6.2 – Unauthenticated PHP Object Injection
The WooCommerce – Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated…
*-2.6.2
2.6.3
14/06/2024
WooCommerce – Social Login <= 2.6.2 – Email Verification due to Insufficient Randomness
The WooCommerce – Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass…
*-2.6.2
2.6.3
14/06/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.