CyberRota Analysis
AI-GeneratedThe WP Social Media Login plugin for WordPress versions up to 1.0.6 is vulnerable due to a lack of verification for social login completions, enabling unauthenticated attackers to gain access to any existing user account, including those of administrators, by simply providing the user's email address. This poses a significant security risk, particularly for sites with elevated privileges or sensitive data. WordPress site administrators using this plugin should prioritize immediate updates or mitigations to prevent unauthorized access.
Original NVD Description
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.