CVE-2024-9501

Wp Social Login and Register Social Counter <= 3.0.7 - Authentication Bypass via WordPress.com OAuth provider

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.


We have discovered 617 live websites that are affected by CVE-2024-9501.

Run a Free Instant Scan




Affected Software

Product  Wp Social
Category Wordpress Plugins
Vulnerable Domains617 live websites (100% of Wp Social install base)
Vulnerable Versions
  • from 0 through 3.0.7
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Oct 26, 2024
  • Updated - Feb 19, 2025

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-9501
United States156 websites



Germany48 websites
India35 websites
Italy27 websites
France27 websites
GB27 websites
Brazil26 websites
Turkey23 websites
Cyprus20 websites
Russia17 websites

Website Distribution by TLD

Number of websites using CVE-2024-9501
.com278 websites
.org29 websites
.com.br21 websites
.it16 websites
.pl12 websites
.ru12 websites
.net11 websites
.fr10 websites
.de9 websites
.com.au7 websites

Websites affected by CVE-2024-9501

Top websites that are affected by CVE-2024-9501. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********************.org United States***,***
*****.com United States***,***
******.org Canada***,***
************.it Italy***,***
***********.com Germany***,***
*******.com United States*,***,***
***********.com Germany*,***,***
***************.com United States*,***,***
*************.com United States*,***,***
******.***.gr Lithuania*,***,***
See full domain list

FAQ

CVE-2024-9501 is Authentication Bypass Using an Alternate Path or Channel in Wp Social
A total of 617 websites have been identified as vulnerable to CVE-2024-9501, based on global website indexing conducted by WebTechSurvey.
The Wp Social is affected by the CVE-2024-9501 vulnerability.
Wp Social versions up to and including 3.0.7 are vulnerable to CVE-2024-9501.