What the vulnerability does
01Description
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
Explanation of Vulnerability in Simple Terms
Log in with Google versions up to 1.4.2 do not properly verify the authenticity of data received during the Google authentication flow. An attacker can forge authentication tokens without valid credentials, gaining unauthorized access to any account on the site. This affects all installations using the vulnerable plugin version.
What an attacker can do
Forge login tokens to gain unauthorized access to any user account without knowing their password.
Potential impact on your site
Attackers can log in as any user, including administrators, compromising the entire site.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities