Heateor Social Login WordPress <= 1.1.39 - Cross-Site Request Forgery
medium
The Heateor Social Login WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.39. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request gr...
- CVSS:
- 4.3
- Affected:
- up to 1.1.39
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2026
CVE-2026-57751 on NVD →
Heateor Social Login WordPress [heateor-social-login] <= 1.1.39 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Heateor Support Heateor Social Login heateor-social-login allows Cross Site Request Forgery.This issue affects Heateor Social Login: from n/a through <= 1.1.39.
- Affected:
- up to 1.1.39
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2025
CVE-2025-68998 on NVD →
Heateor Social Login <= 1.1.39 - Cross-Site Request Forgery
medium
The Heateor Social Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.39. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 1.1.39
- Fix:
- No patched version reported
- Disclosed:
- Dec 26, 2025
CVE-2025-68998 on NVD →
Heateor Social Login WordPress [heateor-social-login] < 1.1.36
unknown
[en] The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing...
- Affected:
- up to 1.1.36
- Fixed in:
- 1.1.36
- Disclosed:
- Nov 6, 2024
CVE-2024-10020 on NVD →
Heateor Social Login WordPress <= 1.1.35 - Authentication Bypass via Disqus OAuth provider
high
The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user...
- CVSS:
- 8.1
- Affected:
- up to 1.1.35
- Fixed in:
- 1.1.36
- Disclosed:
- Nov 5, 2024
CVE-2024-10020 on NVD →
Heateor Social Login WordPress [heateor-social-login] < 1.1.33
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows Stored XSS.This issue affects Heateor Social Login: from n/a through 1.1.32.
- Affected:
- up to 1.1.33
- Fixed in:
- 1.1.33
- Disclosed:
- Jun 8, 2024
CVE-2024-35707 on NVD →
Heateor Social Login WordPress [heateor-social-login] < 1.1.33
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows Cross-Site Scripting (XSS).This issue affects Heateor Social Login: from n/a through 1.1.32.
- Affected:
- up to 1.1.33
- Fixed in:
- 1.1.33
- Disclosed:
- Jun 8, 2024
CVE-2024-35706 on NVD →
Heateor Social Login WordPress <= 1.1.32 - Unauthenticated Stored Cross-Site Scripting
high
The Heateor Social Login WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.1.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...
- CVSS:
- 7.2
- Affected:
- up to 1.1.32
- Fixed in:
- 1.1.33
- Disclosed:
- Jun 6, 2024
CVE-2024-35706 on NVD →
Heateor Social Login WordPress <= 1.1.32 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Heateor Social Login WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.1.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and...
- CVSS:
- 6.4
- Affected:
- up to 1.1.32
- Fixed in:
- 1.1.33
- Disclosed:
- Jun 6, 2024
CVE-2024-35707 on NVD →
Heateor Social Login WordPress <= 1.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Heateor Social Login WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and...
- CVSS:
- 6.4
- Affected:
- up to 1.1.31
- Fixed in:
- 1.1.32
- Disclosed:
- May 8, 2024
CVE-2024-32674 on NVD →
Heateor Social Login WordPress [heateor-social-login] < 1.1.32
unknown
[en] Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.
- Affected:
- up to 1.1.32
- Fixed in:
- 1.1.32
- Disclosed:
- May 8, 2024
CVE-2024-32674 on NVD →
Heateor Social Login WordPress [heateor-social-login] < 1.1.31
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress allows Stored XSS.This issue affects Heateor Social Login WordPress: from n/a through 1.1.30.
- Affected:
- up to 1.1.31
- Fixed in:
- 1.1.31
- Disclosed:
- Feb 10, 2024
CVE-2024-24712 on NVD →
Heateor Social Login <= 1.1.30 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Heateor Social Login WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to and including 1.1.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contri...
- CVSS:
- 6.4
- Affected:
- up to 1.1.30
- Fixed in:
- 1.1.31
- Disclosed:
- Jan 31, 2024
CVE-2024-24712 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database