Ad

CVE-2024-11087

CRITICAL CVSS 3.1: 9.8 EPSS 0.35%
Updated Mar 13, 2025
Miniorange
Parameter Value
CVSS 9.8 (CRITICAL)
Affected Versions before 200.3.9
Type CWE-287 (Improper Authentication)
Vendor Miniorange
Public PoC No

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username and the user does not have an already-existing account for the service returning the token.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Miniorange Social_Login
cpe:2.3:a:miniorange:social_login:*:*:*:*:*:wordpress:*:*
<= 200.3.9