The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Feb 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpwebelite
Wpwebelite woocommerce Social Login |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:wpwebelite:woocommerce_social_login:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpwebelite
Wpwebelite woocommerce Social Login |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T21:25:02.925Z
Reserved: 2024-06-11T15:39:49.296Z
Link: CVE-2024-5871
Updated: 2024-08-01T21:25:02.925Z
Status : Analyzed
Published: 2024-06-15T04:15:13.693
Modified: 2025-02-07T19:41:49.427
Link: CVE-2024-5871
No data.