CVE-2024-9946

Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.68 - Authentication Bypass via Disqus OAuth provider

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they have access to the email and the user does not have an already-existing account for the service returning the token. An attacker cannot authenticate as an administrator by default, but these accounts are also at risk if authentication for administrators has explicitly been allowed via the social login. The vulnerability was partially patched in version 7.13.68.


We have discovered 3,617 live websites that are affected by CVE-2024-9946.

Run a Free Instant Scan




Affected Software

Product  Super Socializer
Category Wordpress Plugins
Vulnerable Domains3,617 live websites (40% of Super Socializer install base)
Vulnerable Versions
  • from 0 through 7.13.68
Vulnerable Versions Count143 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Nov 6, 2024
  • Updated - Feb 19, 2025

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-9946
United States947 websites



Italy320 websites
Russia292 websites
Germany228 websites
France209 websites
GB123 websites
Spain96 websites
Brazil78 websites
Romania76 websites
Poland75 websites

Website Distribution by TLD

Number of websites using CVE-2024-9946
.com1,518 websites
.ru247 websites
.it211 websites
.org153 websites
.net91 websites
.com.br67 websites
.de63 websites
.pl61 websites
.fr57 websites
.co.uk48 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-9946

Top websites that are affected by CVE-2024-9946. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.pro Germany**,***
****.com India**,***
******.com United States***,***
**************.com Spain***,***
*******************.com United States***,***
********.com United States***,***
************************.***.pt Portugal***,***
*************.**.uk GB***,***
****.org Germany***,***
**************.net United States***,***
See full domain list

FAQ

CVE-2024-9946 is Improper Authentication in Super Socializer
A total of 3,617 websites have been identified as vulnerable to CVE-2024-9946, based on global website indexing conducted by WebTechSurvey.
The Super Socializer is affected by the CVE-2024-9946 vulnerability.
Super Socializer versions up to and including 7.13.68 are vulnerable to CVE-2024-9946.