Web3 – Crypto wallet Login & NFT token gating [web3-authentication] < 3.0.0
unknown
[en] The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an adm...
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Feb 12, 2024
CVE-2023-6036 on NVD →
Web3 <= 2.8.0 - Authentication Bypass
critical
The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and including, 2.8.0. This is due to insufficient verification on the 'handle_auth_request' and 'hadle_login_request' functions. This makes it possible for unauthenticated attackers to log...
- CVSS:
- 9.8
- Affected:
- up to 2.8.0
- Fixed in:
- 3.0.0
- Disclosed:
- Jan 17, 2024
CVE-2023-6036 on NVD →
Web3 – Crypto wallet Login & NFT token gating [web3-authentication] < 2.7.0
unknown
[en] The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing us...
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- Jun 30, 2023
CVE-2023-3249 on NVD →
Web3 – Crypto wallet Login & NFT token gating <= 2.6.0 - Authentication Bypass
critical
The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user on...
- CVSS:
- 9.8
- Affected:
- up to 2.6.0
- Fixed in:
- 2.7.0
- Disclosed:
- Jun 29, 2023
CVE-2023-3249 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database