CVE-2024-13182

The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the ‘wp_dp_parse_request’ function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator.

More information : http://localhost:1337/wp-content/plugins/wp-directorybox-manager/elements/login/cs-social-login/cs-social-login.php#L43