What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3.
Explanation of Vulnerability in Simple Terms
WooCommerce Social Login versions up to 2.6.3 contain a deserialization vulnerability in how the plugin processes untrusted data. An attacker can send a specially crafted request to trigger unsafe deserialization, potentially reading sensitive data or modifying site content. No user interaction or authentication is required to exploit this flaw.
What an attacker can do
Read sensitive data or modify site content by sending a malicious request.
Potential impact on your site
Attackers can access private information or alter site data without logging in.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities