Description
WordPress Plugin WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently log in as any existing user on the site, including administrator, if they know the email address. WordPress Plugin WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) version 7.6.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 7.6.5 or latest
References
Related Vulnerabilities
MediaWiki Other Vulnerability (CVE-2013-4568)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1000862)
WordPress Plugin Image Widget Unspecified Vulnerability (4.1.2)
MySQL CVE-2014-0386 Vulnerability (CVE-2014-0386)
Atlassian Jira Missing Authorization Vulnerability (CVE-2020-14185)