Critical severity9.8NVD Advisory· Published Jul 20, 2024· Updated Jun 17, 2026
CVE-2024-6636
CVE-2024-6636
Description
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator while registering for an account.
Affected products
3cpe:2.3:a:wpwebelite:woocommerce_social_login:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:wpwebelite:woocommerce_social_login:*:*:*:*:*:wordpress:*:*range: <2.7.4
- (no CPE)range: 0
- Range: <=2.7.3
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.