cbcvebase.

Roxnor Wp Social Login And Register Social Counter vulnerabilities

4 known vulnerabilities affecting roxnor/wp_social_login_and_register_social_counter.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2024-9501P2CRITICALCVSS 9.8≤ 3.0.72024-10-26
CVE-2024-9501 [CRITICAL] CWE-288 CVE-2024-9501: The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such a
nvd
CVE-2025-13620P4MEDIUMCVSS 5.3≤ 3.1.32025-12-05
CVE-2025-13620 [MEDIUM] CWE-862 CVE-2025-13620: The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing author The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback set to __return_true and lacking
nvd
CVE-2024-1763P4MEDIUMCVSS 5.3≤ 3.0.02024-03-13
CVE-2024-1763 [MEDIUM] CWE-862 CVE-2024-1763: The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized m The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable certain providers for the social share
nvd
CVE-2025-1506P4MEDIUMCVSS 4.3≤ 3.1.02025-02-28
CVE-2025-1506 [MEDIUM] CWE-352 CVE-2025-1506: The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Req The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function. This makes it possible for unauthenticated attackers to update social login provider settings via
nvd
Roxnor Wp Social Login And Register Social Counter vulnerabilities | cvebase