S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-2982 Scanner

Detects 'Authentication Bypass' vulnerability in WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) affects v. through 7.6.4.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-2982
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the email address associated with that user. This was partially patched in version 7.6.4 and fully patched in version 7.6.5.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)by cyberlord92
0
Updated Aug 22, 2026View on NVD →
Detail

WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) is a software plugin used by developers to add social media login and registration functionality to their WordPress websites. The plugin allows website users to easily sign in to the site using their existing social media accounts, rather than creating a new account. With over 1 million active installations, this plugin has become a popular solution for website owners seeking to streamline their user registration process and offer more convenience to their users.

One of the vulnerabilities detected in this plugin is CVE-2023-2982. This vulnerability is due to insufficient encryption on the user being supplied during a login validated through the plugin. As a result, unauthenticated attackers can easily log in as any existing user on the site if they know the email address associated with that user. This type of vulnerability can lead to major security and privacy breaches, exposing sensitive user data and putting users at risk.

Exploitation of this vulnerability can result in disastrous consequences for website owners. Unauthenticated attackers can hack into the website and access sensitive information such as usernames, passwords, and personal data, including email addresses. They can also alter the site's content or shut down the entire website altogether, causing significant financial loss to business owners.

Thanks to the pro features of s4e.io, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. With its advanced scanning and reporting tools, s4e.io can help website owners stay on top of their website's security and protect against vulnerabilities like CVE-2023-2982. By keeping their website secure, website owners can ensure the safety and privacy of their users while maintaining the integrity of their business.

 

REFERENCES

Solution Advice

One way to protect against this vulnerability is to update the WordPress Social Login and Register plugin to the latest version (7.6.5). Additionally, website owners are advised to take the following precautions: 

  • Implement a password manager to ensure that user passwords are sufficiently encrypted and secure.
  • Use two-factor authentication to add an extra layer of security.
  • Regularly monitor user accounts to detect any suspicious activity.
  • Run regular security scans to detect and remove any vulnerabilities before they can be exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.