CVE-2024-6636
CVE-2024-6636 affects the WooCommerce Social Login plugin, allowing unauthorized data modification. An unauthenticated attacker can exploit this vulnerability in versions up to 2.7.3 to escalate privileges to Administrator during account registration. The vulnerability resides in the 'woo_slg_login_email' function due to a missing capability check, leading to a critical security flaw. Despite a low SVRS of 30, indicating less immediate threat activity compared to vulnerabilities with scores above 80, the potential for privilege escalation makes this a significant concern for websites using the affected plugin. Website owners should promptly update to a patched version to mitigate the risk of unauthorized administrative access. The potential impact includes full control over the WordPress site by malicious actors. Immediate patching is recommended regardless of the SVRS score due to the inherent risk of unauthorized privilege escalation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.