Heateor Social Login WordPress <= 1.1.35 - Authentication Bypass via Disqus OAuth provider
Description
Authentication bypass in Heateor Social Login WordPress plugin up to 1.1.35 allows unauthenticated attackers to log in as any existing user via insufficient token verification.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authentication bypass in Heateor Social Login WordPress plugin up to 1.1.35 allows unauthenticated attackers to log in as any existing user via insufficient token verification.
Vulnerability
The Heateor Social Login WordPress plugin (slug: social-login) is vulnerable to authentication bypass in all versions up to and including 1.1.35 [1]. The flaw lies in insufficient verification of the user returned by the social login token. Attackers can authenticate as any existing user on the site if they have access to the user's email address and the user does not already have an account for the service that returned the token.
Exploitation
An unauthenticated attacker can exploit this vulnerability by obtaining the email address of a target user. The attacker then uses a social login provider to generate a token with that email. Due to insufficient verification, the plugin accepts the token and logs the attacker in as the target user. By default, authentication as an administrator is not possible unless the plugin configuration explicitly allows admin authentication.
Impact
Successful exploitation allows the attacker to gain unauthorized access to any user account on the WordPress site, including subscriber, contributor, or other roles. If administrator authentication is enabled via the plugin settings, admin accounts are also at risk. The attacker can then perform actions as that user, potentially leading to data theft, content manipulation, or further privilege escalation.
Mitigation
The plugin has been closed and removed from the WordPress.org plugin directory as of June 6, 2018, with no patched version available [1]. Users who have the plugin installed should uninstall it immediately and consider using an alternative social login plugin that is actively maintained.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <=1.1.35
- heateor/Heateor Social Login WordPressv5Range: 0
Patches
1r3177729social-loginThis plugin has been removed from the WordPress.org directory on 2018-06-06 (reason: Unused). No patched version is being distributed through the official directory. Users who have it installed should uninstall it.
Source: api.wordpress.org · directory page
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.