Threat Advisory

Critical Security Flaw in Social Login Plugin for WordPress Exposes Users' Accounts

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

 

Summary: [/subscribe_to_unlock_form]

 

Summary: [emaillocker id="1283"]

The two critical security vulnerabilities found in popular WordPress plugins. The first vulnerability affects miniOrange's Social Login and Register plugin for WordPress. The flaw tracked as CVE-2023-2982, allows an attacker to bypass authentication and login as any user if they have access to the user's email address. This vulnerability was addressed in version 7.6.5 of the plugin, released on June 14, 2023. If the compromised account belongs to a site administrator, it could result in a complete compromise. The miniOrange plugin is used on over 30,000 sites.

The second vulnerability affects the LearnDash LMS plugin, which is widely used on WordPress with over 100,000 active installations. Tracked as CVE-2023-3105, the flaw allows any user with an existing account to reset arbitrary user passwords, including those with administrator access. The vulnerability was patched in version 4.6.0.1 of the plugin, released on June 6, 2023.

 

Recommendations:

We strongly recommend you download and apply the patch provided by WordPress version 7.6.5.

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/06/critical-security-flaw-in-social-login.html

[/emaillocker]
crossmenu