plugin

Web3 Authentication Vulnerabilities

4 known security issues reported for the Web3 Authentication WordPress plugin. Most recent disclosed Feb 12, 2024.

2 critical

Running Web3 Authentication on your site? Check whether your installed version is affected.

Scan your site free

Web3 &#8211; Crypto wallet Login &amp; NFT token gating [web3-authentication] < 3.0.0

unknown

[en] The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an adm...

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Feb 12, 2024

CVE-2023-6036 on NVD →

Web3 <= 2.8.0 - Authentication Bypass

critical

The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and including, 2.8.0. This is due to insufficient verification on the 'handle_auth_request' and 'hadle_login_request' functions. This makes it possible for unauthenticated attackers to log...

CVSS:
9.8
Affected:
up to 2.8.0
Fixed in:
3.0.0
Disclosed:
Jan 17, 2024

CVE-2023-6036 on NVD →

Web3 &#8211; Crypto wallet Login &amp; NFT token gating [web3-authentication] < 2.7.0

unknown

[en] The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing us...

Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Jun 30, 2023

CVE-2023-3249 on NVD →

Web3 – Crypto wallet Login & NFT token gating <= 2.6.0 - Authentication Bypass

critical

The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user on...

CVSS:
9.8
Affected:
up to 2.6.0
Fixed in:
2.7.0
Disclosed:
Jun 29, 2023

CVE-2023-3249 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database