CVE-2023-2982 is an authentication bypass vulnerability in the WordPress Social Login and Register plugin (Discord, Google, Twitter, LinkedIn) up to and including version 7.6.4. The vulnerability arises from insufficient encryption of the user data supplied during login validation, allowing an unauthenticated attacker to log in as any existing user, including administrators, if the email address is known. The issue was partially patched in 7.6.4 and fully patched in 7.6.5.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides an exploit for CVE-2023-2982, targeting the WordPress Social Login and Register plugin (versions <=7.6.4). The exploit is implemented in a single Python script (CVE-2023-2982.py), which can either use a supplied email address or attempt to discover email addresses on the target site using external tools (Katana and Nuclei). The script crafts an AES-encrypted, base64-encoded email and submits it to the plugin's vulnerable endpoint ('/?option=moopenid') to bypass authentication and log in as any user, including administrators. If successful, it generates a customized HTML file (based on login.html) that can be used to complete the login process in a browser. The repository also includes a README.md with detailed usage instructions and background on the vulnerability. The main attack vector is network-based, exploiting a web application endpoint. No hardcoded IPs or domains are present; the target is specified by the user at runtime.
This repository provides an operational exploit for CVE-2023-2982, targeting the WordPress Social Login and Register plugin (versions <= 7.6.4). The main exploit script (CVE-2023-2982.py) can either use a supplied email address or automatically crawl the target website for email addresses using external tools (katana and nuclei). It then crafts a specially encrypted and encoded email value and submits it to the vulnerable login endpoint ('/?option=moopenid') to attempt authentication bypass. If successful, it generates a customized HTML file (based on login.html) that can be used to log in as the compromised user. The repository includes a YAML template for email extraction, a requirements file for dependencies, and documentation in the README. The exploit is operational, automating both email discovery and exploitation, and is effective against unpatched WordPress sites running the affected plugin version.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.