Wp Social Login and Register Social Counter [wp-social] < 3.1.4
unknown
[en] The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callba...
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Dec 5, 2025
CVE-2025-13620 on NVD →
Wp Social Login and Register Social Counter <= 3.1.3 - Missing Authorization in Cache REST Endpoints to Social Counter Tampering
medium
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback se...
- CVSS:
- 5.3
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Dec 4, 2025
CVE-2025-13620 on NVD →
Wp Social Login and Register Social Counter <= 3.1.0 - Cross-Site Request Forgery to Settings Update
medium
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function. This makes it possible for unauthenticated attackers to update so...
- CVSS:
- 4.3
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.1
- Disclosed:
- Feb 27, 2025
CVE-2025-1506 on NVD →
Wp Social Login and Register Social Counter [wp-social] < 3.0.8
unknown
[en] The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as a...
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
- Disclosed:
- Oct 26, 2024
CVE-2024-9501 on NVD →
Wp Social Login and Register Social Counter <= 3.0.7 - Authentication Bypass via WordPress.com OAuth provider
critical
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any ex...
- CVSS:
- 9.8
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.8
- Disclosed:
- Oct 25, 2024
CVE-2024-9501 on NVD →
Wp Social Login and Register Social Counter [wp-social] < 3.0.1
unknown
[en] The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable c...
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Mar 13, 2024
CVE-2024-1763 on NVD →
Wp Social Login and Register Social Counter <= 3.0.0 - Missing Authorization to Unauthenticated Social Login/Share Status Update
medium
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable certai...
- CVSS:
- 6.5
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.1
- Disclosed:
- Feb 29, 2024
CVE-2024-1763 on NVD →
Wp Social Login and Register Social Counter [wp-social] < 2.0
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp Social Login and Register Social Counter: from n/a through 1.9.0.
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Jan 19, 2024
CVE-2022-47160 on NVD →
Wp Social <= 1.9.0 - Authenticated (Subscriber+) Information Disclosure
medium
The Wp Social plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.9.0. This is due to missing capability checks on the 'export_users_content_csv' function. This makes it possible for authenticated attackers with minimal permissions such as subscribers to export user content su...
- CVSS:
- 6.8
- Affected:
- up to 1.9.0
- Fixed in:
- 2.0
- Disclosed:
- Dec 14, 2022
CVE-2022-47160 on NVD →
Wp Social Login and Register Social Counter [wp-social] < 3.1.1
unknown
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
CVE-2025-1506 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database