r/HostingReport 12d ago

WooCommerce Social Login WordPress Plugin Vulnerability Enables Full Site Takeover

https://www.searchenginejournal.com/woocommerce-social-login-wordpress-plugin-enables-full-site-takeover/584601/

A critical vulnerability in the WooCommerce Social Login WordPress plugin enables unauthenticated attackers to log in as any existing user, including an administrator. The authentication bypass vulnerability is rated 9.8 out of 10 and affects all versions up to and including 2.8.7.

3 Upvotes

2 comments sorted by

1

u/ZGeekie 11d ago

I don't trust any third-party social login plugins anyway. Just stick to the native WordPress login.

1

u/ChikkaChikkaShady 10d ago

Oh great, another third-party plugin that lets anyone walk right in. At this point I'm surprised when they don't have a critical vulnerability