CyberRota Analysis
AI-GeneratedThe Social Login & Sharing buttons with Analytics By SoClever WordPress plugin versions up to 1.2.0 are vulnerable due to a lack of authentication, authorization, and nonce checks in a publicly accessible login handler. This flaw allows unauthenticated attackers to gain a valid session as any existing user, including administrators, potentially compromising the entire site. WordPress site administrators and users of this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.
Original NVD Description
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obtained without needing to know any account details at all.