WooCommerce - Social Login <= 2.6.2 - Email Verification due to Insufficient Randomness
2024-06-14 00:00
István MártonStrategic Overview
StatusPatched in 2.6.3
Affected PluginWooCommerce - Social Login
Affected Version
<= 2.6.2CVSS6.5Medium
CVE
CVE-2024-5868Vulnerability Overview
The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.
Technical Analysis
REMEDIATION: Update to version 2.6.3, or a newer patched version --- IDENTIFIER: CWE-330 (Use of Insufficiently Random Values) The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C