CVE-2024-37502 MEDIUM

CVE-2024-37502: WordPress Social Login plugin <= 2.6.3 - PHP Object Injection vulnerability

Vendor Wpweb
Product WooCommerce Social Login
Weakness CWE-502 · Unsafe deserialization
Published July 9, 2024
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3.

Explanation of Vulnerability in Simple Terms

02Summary

WooCommerce Social Login versions up to 2.6.3 contain a deserialization vulnerability in how the plugin processes untrusted data. An attacker can send a specially crafted request to trigger unsafe deserialization, potentially reading sensitive data or modifying site content. No user interaction or authentication is required to exploit this flaw.

What an attacker can do

03Attacker Capabilities

Read sensitive data or modify site content by sending a malicious request.

Potential impact on your site

04Site Impact

Attackers can access private information or alter site data without logging in.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

July 9, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE