• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
critical security flaw in social login plugin for wordpress exposes

Critical Security Flaw in Social Login Plugin for WordPress Exposes Users’ Accounts

You are here: Home / General Cyber Security News / Critical Security Flaw in Social Login Plugin for WordPress Exposes Users’ Accounts
June 29, 2023

A critical security flaw has been disclosed in miniOrange’s Social Login and Sign-up plugin for WordPress that could enable a malicious actor to log in as any person-offered details about email handle is now acknowledged.

Tracked as CVE-2023-2982 (CVSS rating: 9.8), the authentication bypass flaw impacts all versions of the plugin, together with and prior to 7.6.4. It was resolved on June 14, 2023, with the launch of version 7.6.5 subsequent liable disclosure on June 2, 2023.

“The vulnerability helps make it probable for an unauthenticated attacker to achieve access to any account on a site such as accounts utilised to administer the web page, if the attacker knows, or can come across, the associated email deal with,” Wordfence researcher István Márton stated.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The issue is rooted in the simple fact that the encryption important utilised to protected the data all through login utilizing social media accounts is tricky-coded, therefore primary to a state of affairs exactly where attackers could make a valid ask for with a thoroughly encrypted email address made use of to detect the user.

Really should the account belong to the WordPress web site administrator, it could outcome in a complete compromise. The plugin is employed on a lot more than 30,000 sites.

Cybersecurity

The advisory follows the discovery of a significant-severity flaw influencing LearnDash LMS plugin, a WordPress plugin with about 100,000 lively installations, that could allow any consumer with an existing account to reset arbitrary user passwords, which include those with administrator entry.

The bug (CVE-2023-3105, CVSS score: 8.8), has been patched in edition 4.6..1 that was shipped on June 6, 2023.

It also will come weeks immediately after Patchstack in depth a cross-site ask for forgery (CSRF) vulnerability in the UpdraftPlus plugin (CVE-2023-32960, CVSS rating: 7.1) that could allow an unauthenticated attacker to steal delicate information and elevate privileges by tricking a person with administrative permissions to go to a crafted WordPress web site URL.

Found this write-up exciting? Observe us on Twitter  and LinkedIn to read through much more exclusive content material we post.


Some areas of this article are sourced from:
thehackernews.com

Previous Post: «newly uncovered thirdeye windows based malware steals sensitive data Newly Uncovered ThirdEye Windows-Based Malware Steals Sensitive Data
Next Post: Android Spy App LetMeSpy Suffers Major Data Breach, Exposing Users’ Personal Data android spy app letmespy suffers major data breach, exposing users'»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.