WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT
critical
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or valid...
- CVSS:
- 9.8
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- Aug 1, 2026
CVE-2026-8457 on NVD →
WooCommerce Social Login <= 2.8.2 - Cross-Site Request Forgery
medium
The WooCommerce - Social Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a...
- CVSS:
- 4.3
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.3
- Disclosed:
- Apr 16, 2025
CVE-2025-39472 on NVD →
WooCommerce - Social Login [woo-social-login] <= 2.8.2 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WPWeb WooCommerce Social Login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a before 2.8.3.
- Affected:
- up to 2.8.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 16, 2025
CVE-2025-39472 on NVD →
WooCommerce - Social Login [woo-social-login] < 2.7.8
unknown
[en] The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user...
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Nov 5, 2024
CVE-2024-10114 on NVD →
Social Login - WordPress / WooCommerce Plugin <= 2.7.7 - Authentication Bypass via WordPress.com OAuth provider
high
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on th...
- CVSS:
- 8.1
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.8
- Disclosed:
- Nov 4, 2024
CVE-2024-10114 on NVD →
WooCommerce - Social Login [woo-social-login] < 2.7.6
unknown
[en] The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for unauthenticated attackers to log in as any e...
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.6
- Disclosed:
- Aug 10, 2024
CVE-2024-7503 on NVD →
WooCommerce - Social Login <= 2.7.5 - Authentication Bypass to Account Takeover
critical
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for unauthenticated attackers to log in as any existi...
- CVSS:
- 9.8
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.6
- Disclosed:
- Aug 9, 2024
CVE-2024-7503 on NVD →
WooCommerce - Social Login [woo-social-login] < 2.7.4
unknown
[en] The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password...
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Jul 20, 2024
CVE-2024-6637 on NVD →
WooCommerce - Social Login [woo-social-login] < 2.7.4
unknown
[en] The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding...
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Jul 20, 2024
CVE-2024-6635 on NVD →
WooCommerce - Social Login [woo-social-login] < 2.7.4
unknown
[en] The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrato...
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Jul 20, 2024
CVE-2024-6636 on NVD →
WooCommerce - Social Login <= 2.7.3 - Missing Authorization to Unauthenticated Privilege Escalation
critical
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator whi...
- CVSS:
- 9.8
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.4
- Disclosed:
- Jul 19, 2024
CVE-2024-6636 on NVD →
WooCommerce - Social Login <= 2.7.3 - Unauthenticated Authentication Bypass
high
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an ad...
- CVSS:
- 7.3
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.4
- Disclosed:
- Jul 19, 2024
CVE-2024-6635 on NVD →
WooCommerce - Social Login <= 2.7.3 - Unauthenticated Privilege Escalation via One-Time Password
high
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for...
- CVSS:
- 7.3
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.4
- Disclosed:
- Jul 19, 2024
CVE-2024-6637 on NVD →
WooCommerce - Social Login [woo-social-login] < 2.7.0
unknown
[en] Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login.This issue affects WooCommerce Social Login: from n/a through 2.6.3.
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- Jul 9, 2024
CVE-2024-37502 on NVD →
WooCommerce Social Login <= 2.6.3 - Unauthenticated PHP Object Injection
critical
The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP ch...
- CVSS:
- 9.8
- Affected:
- up to 2.6.3
- Fixed in:
- 2.7.0
- Disclosed:
- Jul 5, 2024
CVE-2024-37502 on NVD →
WooCommerce - Social Login [woo-social-login] < 2.6.3
unknown
[en] The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chai...
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- Jun 15, 2024
CVE-2024-5871 on NVD →
WooCommerce - Social Login [woo-social-login] < 2.6.3
unknown
[en] The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- Jun 15, 2024
CVE-2024-5868 on NVD →
WooCommerce - Social Login <= 2.6.2 - Unauthenticated PHP Object Injection
critical
The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is...
- CVSS:
- 9.8
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Jun 14, 2024
CVE-2024-5871 on NVD →
WooCommerce - Social Login <= 2.6.2 - Email Verification due to Insufficient Randomness
medium
The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.
- CVSS:
- 6.5
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Jun 14, 2024
CVE-2024-5868 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database