The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable certain providers for the social share and login features.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpmet
Wpmet wp Social Login And Register Social Counter |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:wpmet:wp_social_login_and_register_social_counter:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpmet
Wpmet wp Social Login And Register Social Counter |

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-03-13T15:26:48.783Z
Updated: 2024-08-08T18:40:26.695Z
Reserved: 2024-02-22T15:33:56.843Z
Link: CVE-2024-1763

Updated: 2024-08-01T18:48:22.004Z

Status : Analyzed
Published: 2024-03-13T16:15:26.863
Modified: 2025-03-20T11:05:42.940
Link: CVE-2024-1763

No data.