Description
WordPress Plugin WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently log in as any existing user on the site, including administrator, if they know the email address. WordPress Plugin WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) version 7.6.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 7.6.5 or latest
References
Related Vulnerabilities
Python CVE-2019-16056 Vulnerability (CVE-2019-16056)
WordPress Plugin Mailster-Email Newsletter for WordPress Local File Inclusion (4.0.6)
Liferay Portal Missing Authorization Vulnerability (CVE-2022-38512)
WordPress Plugin Download Plugin Arbitrary Directory Download (1.0.1)
Zope Web Application Server Resource Management Errors Vulnerability (CVE-2008-5102)