Sign In With Google <= 1.8.0 - Authentication Bypass in authenticate_user
criticalThe Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the 'authenticate_user' user function not implementing sufficient null value checks when setting the access token and user information. This makes it possible for unauthenticat...
- CVSS:
- 9.8
- Affected:
- up to 1.8.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 11, 2024