VYPR
Unrated severityNVD Advisory· Published Nov 6, 2024· Updated Apr 8, 2026

Heateor Social Login WordPress <= 1.1.35 - Authentication Bypass via Disqus OAuth provider

CVE-2024-10020

Description

Authentication bypass in Heateor Social Login WordPress plugin up to 1.1.35 allows unauthenticated attackers to log in as any existing user via insufficient token verification.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authentication bypass in Heateor Social Login WordPress plugin up to 1.1.35 allows unauthenticated attackers to log in as any existing user via insufficient token verification.

Vulnerability

The Heateor Social Login WordPress plugin (slug: social-login) is vulnerable to authentication bypass in all versions up to and including 1.1.35 [1]. The flaw lies in insufficient verification of the user returned by the social login token. Attackers can authenticate as any existing user on the site if they have access to the user's email address and the user does not already have an account for the service that returned the token.

Exploitation

An unauthenticated attacker can exploit this vulnerability by obtaining the email address of a target user. The attacker then uses a social login provider to generate a token with that email. Due to insufficient verification, the plugin accepts the token and logs the attacker in as the target user. By default, authentication as an administrator is not possible unless the plugin configuration explicitly allows admin authentication.

Impact

Successful exploitation allows the attacker to gain unauthorized access to any user account on the WordPress site, including subscriber, contributor, or other roles. If administrator authentication is enabled via the plugin settings, admin accounts are also at risk. The attacker can then perform actions as that user, potentially leading to data theft, content manipulation, or further privilege escalation.

Mitigation

The plugin has been closed and removed from the WordPress.org plugin directory as of June 6, 2018, with no patched version available [1]. Users who have the plugin installed should uninstall it immediately and consider using an alternative social login plugin that is actively maintained.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

1
Plugin removedsocial-loginsocial-login

This plugin has been removed from the WordPress.org directory on 2018-06-06 (reason: Unused). No patched version is being distributed through the official directory. Users who have it installed should uninstall it.

Source: api.wordpress.org · directory page

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.