CVE-2024-11015
Sign In With Google <= 1.8.0 - Authentication Bypass in authenticate_user
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 0.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 Dec 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the 'authenticate_user' user function not implementing sufficient null value checks when setting the access token and user information. This makes it possible for unauthenticated attackers to log in as the first user who has signed in using Google OAuth, which could be the site administrator.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
tarecord · Sign In With GoogleWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →