Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total6
Critical1
High2
Medium3
Reset
Showing 1-6 of 6 records
Threat Entry Updated 2025-09-11

CVE-2025-9857 - Social Login Plugin

The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Heateor_Facebook_Login' shortcode in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Social Login

CVE-2025-9857

MEDIUM CVSS 6.4 2025-09-10
Threat Entry Updated 2025-03-13

CVE-2024-11087 - Social Login Plugin

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username and the user does not have an already-existing account for the service returning the token.

PLUGIN Social Login

CVE-2024-11087

HIGH CVSS 8.1 2025-03-08
Threat Entry Updated 2024-12-06

CVE-2024-10961 - Social Login Plugin

The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

PLUGIN Social Login

CVE-2024-10961

CRITICAL CVSS 9.8 2024-11-23
Threat Entry Updated 2024-11-08

CVE-2024-10020 - Social Login Plugin

The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they have access to the email and the user does not have an already-existing account for the service returning the token. An attacker cannot authenticate as an administrator by default, but these accounts are also…

PLUGIN Social Login

CVE-2024-10020

HIGH CVSS 8.1 2024-11-06
Threat Entry Updated 2025-06-04

CVE-2024-32674 - Social Login Plugin

Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

PLUGIN Social Login

CVE-2024-32674

MEDIUM CVSS 5.4 2024-05-08
Threat Entry Updated 2024-11-21

CVE-2024-24712 - Social Login Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress allows Stored XSS.This issue affects Heateor Social Login WordPress: from n/a through 1.1.30.

PLUGIN Social Login

CVE-2024-24712

MEDIUM CVSS 6.5 2024-02-10
Scroll to top