plugin

Wp Social Vulnerabilities

10 known security issues reported for the Wp Social WordPress plugin. Most recent disclosed Dec 5, 2025.

1 critical 4 medium

Running Wp Social on your site? Check whether your installed version is affected.

Scan your site free

Wp Social Login and Register Social Counter [wp-social] < 3.1.4

unknown

[en] The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callba...

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Dec 5, 2025

CVE-2025-13620 on NVD →

Wp Social Login and Register Social Counter <= 3.1.3 - Missing Authorization in Cache REST Endpoints to Social Counter Tampering

medium

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback se...

CVSS:
5.3
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Dec 4, 2025

CVE-2025-13620 on NVD →

Wp Social Login and Register Social Counter <= 3.1.0 - Cross-Site Request Forgery to Settings Update

medium

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function. This makes it possible for unauthenticated attackers to update so...

CVSS:
4.3
Affected:
up to 3.1.0
Fixed in:
3.1.1
Disclosed:
Feb 27, 2025

CVE-2025-1506 on NVD →

Wp Social Login and Register Social Counter [wp-social] < 3.0.8

unknown

[en] The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as a...

Affected:
up to 3.0.8
Fixed in:
3.0.8
Disclosed:
Oct 26, 2024

CVE-2024-9501 on NVD →

Wp Social Login and Register Social Counter <= 3.0.7 - Authentication Bypass via WordPress.com OAuth provider

critical

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any ex...

CVSS:
9.8
Affected:
up to 3.0.7
Fixed in:
3.0.8
Disclosed:
Oct 25, 2024

CVE-2024-9501 on NVD →

Wp Social Login and Register Social Counter [wp-social] < 3.0.1

unknown

[en] The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable c...

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Mar 13, 2024

CVE-2024-1763 on NVD →

Wp Social Login and Register Social Counter <= 3.0.0 - Missing Authorization to Unauthenticated Social Login/Share Status Update

medium

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable certai...

CVSS:
6.5
Affected:
up to 3.0.0
Fixed in:
3.0.1
Disclosed:
Feb 29, 2024

CVE-2024-1763 on NVD →

Wp Social Login and Register Social Counter [wp-social] < 2.0

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp Social Login and Register Social Counter: from n/a through 1.9.0.

Affected:
up to 2.0
Fixed in:
2.0
Disclosed:
Jan 19, 2024

CVE-2022-47160 on NVD →

Wp Social <= 1.9.0 - Authenticated (Subscriber+) Information Disclosure

medium

The Wp Social plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.9.0. This is due to missing capability checks on the 'export_users_content_csv' function. This makes it possible for authenticated attackers with minimal permissions such as subscribers to export user content su...

CVSS:
6.8
Affected:
up to 1.9.0
Fixed in:
2.0
Disclosed:
Dec 14, 2022

CVE-2022-47160 on NVD →

Wp Social Login and Register Social Counter [wp-social] < 3.1.1

unknown
Affected:
up to 3.1.1
Fixed in:
3.1.1

CVE-2025-1506 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database