Description
WordPress Plugin WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently log in as any existing user on the site, including administrator, if they know the email address. WordPress Plugin WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) version 7.6.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 7.6.5 or latest
References
Related Vulnerabilities
WordPress Plugin Contact Form 7 Multi-Step Addon Malicious Code (1.0.5)
WordPress Plugin Survey Maker-Best WordPress Survey Unspecified Vulnerability (3.2.0)
WordPress Plugin GD Rating System Cross-Site Scripting (2.0.2)
Moodle CVE-2020-25698 Vulnerability (CVE-2020-25698)
WordPress Plugin LearnDash LMS Cross-Site Scripting (3.1.1.1)