VendorsWPWeb Elitewoocommerce_social_loginall versions
Vulnerabilities

WPWeb Elite WooCommerce Social Login

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-5871
WooCommerce - Social Login <= 2.6.2 - Unauthenticated PHP Object Injection
Published 2024-06-15 · Modified
9.8EPSS 0.007
CVE-2024-7503
WooCommerce - Social Login <= 2.7.5 - Authentication Bypass to Account Takeover
Published 2024-08-10 · Analyzed
9.8EPSS 0.006
CVE-2024-6636
WooCommerce - Social Login <= 2.7.3 - Missing Authorization to Unauthenticated Privilege Escalation
Published 2024-07-20 · Analyzed
9.8EPSS 0.005
CVE-2025-39472
WordPress WooCommerce Social Login plugin < 2.8.3 - Cross Site Request Forgery (CSRF) vulnerability
Published 2025-04-16 · Modified
8.8EPSS 0.002
CVE-2024-10114
Social Login - WordPress / WooCommerce Plugin <= 2.7.7 - Authentication Bypass via WordPress.com OAuth provider
Published 2024-11-05 · Analyzed
8.1EPSS 0.005
CVE-2024-37502
WordPress Social Login plugin <= 2.6.3 - PHP Object Injection vulnerability
Published 2024-07-09 · Modified
7.5EPSS 0.003
CVE-2024-6635
WooCommerce - Social Login <= 2.7.3 - Unauthenticated Authentication Bypass
Published 2024-07-20 · Analyzed
7.3EPSS 0.004
CVE-2024-6637
WooCommerce - Social Login <= 2.7.3 - Unauthenticated Privilege Escalation via One-Time Password
Published 2024-07-20 · Analyzed
7.3EPSS 0.004
CVE-2024-5868
WooCommerce - Social Login <= 2.6.2 - Email Verification due to Insufficient Randomness
Published 2024-06-15 · Modified
6.5EPSS 0.003