CyberRota Analysis
AI-GeneratedThe login-social WordPress plugin versions up to 1.0.4 are vulnerable due to inadequate validation of password-reset requests, allowing unauthenticated attackers to reset any user's password or gain access to accounts, including those of administrators. This flaw poses a significant risk of site takeover, making it critical for WordPress site administrators and users of the affected plugin to prioritize immediate updates or mitigations. Organizations relying on this plugin should assess their exposure and implement necessary security measures to protect against potential exploitation.
Original NVD Description
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.