Vulnerabilities and security researches forwp-social wp-social
Direction: descendingJan 11, 2026
Wp Social Login and Register Social Counter # CVE-2025-13620
- CVE, Research URL
- Application
- Date
- Dec 05, 2025
- Research Description
- The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback set to __return_true and lacking capability or nonce validation in their handlers. This makes it possible for unauthenticated attackers to clear or overwrite the social counter cache via crafted REST requests.
- Affected versions
-
max 3.1.4.
- Status
-
vulnerable
Feb 28, 2025
Wp Social Login and Register Social Counter # CVE-2025-1506
- CVE, Research URL
- Application
- Date
- Feb 28, 2025
- Research Description
- The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function. This makes it possible for unauthenticated attackers to update social login provider settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 3.1.1.
- Status
-
vulnerable
Oct 28, 2024
Wp Social Login and Register Social Counter # CVE-2024-9501
- CVE, Research URL
- Application
- Date
- Oct 26, 2024
- Research Description
- The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.
- Affected versions
-
max 3.0.8.
- Status
-
vulnerable
Jun 07, 2024
Wp Social Login and Register Social Counter # CVE-2024-1763
- CVE, Research URL
- Application
- Date
- Mar 13, 2024
- Research Description
- The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable certain providers for the social share and login features.
- Affected versions
-
max 3.0.1.
- Status
-
vulnerable
Wp Social Login and Register Social Counter # CVE-2022-47160
- CVE, Research URL
- Application
- Date
- Jan 19, 2024
- Research Description
- Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp Social Login and Register Social Counter: from n/a through 1.9.0.
- Affected versions
-
max 2.0.
- Status
-
vulnerable