Web3 – Crypto wallet Login & NFT token gating < 3.0.0 - Authentication Bypass
Description
The Web3 WordPress plugin before 3.0.0 contains an authentication bypass allowing unauthenticated attackers to log in as any user, including administrators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Web3 WordPress plugin before 3.0.0 contains an authentication bypass allowing unauthenticated attackers to log in as any user, including administrators.
Vulnerability
The Web3 WordPress plugin before version 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow. The flaw resides in the functions handle_auth_request and hadle_login_request, which fail to properly verify the user's identity, allowing unauthenticated attackers to bypass authentication [1].
Exploitation
An attacker can exploit this vulnerability by sending a crafted login request to the vulnerable endpoints. The attacker only needs to know the username of an existing user (e.g., an administrator) to log in as that user without any prior authentication or user interaction [1].
Impact
Successful exploitation allows an attacker to log in as any existing user on the WordPress site, including administrators. This grants full access to the site, enabling the attacker to modify content, install malicious plugins, or take complete control of the site [1].
Mitigation
The vulnerability is fixed in version 3.0.0 of the Web3 plugin, released on 2024-01-17. Users should update to this version immediately. No other workarounds are available [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- WordPress/Web3description
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1- wpscan.com/vulnerability/7f30ab20-805b-422c-a9a5-21d39c570ee4/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.