CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.3. It affects WordPress. Exploitation may require the attacker to be authenticated.
CVE
CVE-2024-6637
Severity
HIGH
CVSS
7.3
EPSS
0.36%
WordPress
Original NVD Description
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for any user, except an Administrator, if they know the email of user.
Related CVEs
Other vulnerabilities affecting the same vendor(s)