The Wordpress Social Login Project develops a plugin that extends WordPress authentication by enabling login through social media accounts, presenting an application-layer attack surface tied to third-party identity integration. Vulnerabilities in this product center on cross-site scripting flaws arising from improper input neutralization during page generation, a class typical of web applications handling user-supplied or redirected authentication data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wordpress Social Login Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4773MEDIUM The WordPress Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wordpress_social_login_meta' shortcode in versions up to, and including, 3.0.4 | Sep 6, 2023 | 6.4 | 20 | NO | NO |
CVE-2014-4576MEDIUM Cross-site scripting (XSS) vulnerability in services/diagnostics.php in the WordPress Social Login plugin 2.0.3 and earlier for WordPress allows remote attackers to inject arbitrar | Jul 2, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wordpress Social Login Project.
Media articles that mention a CVE ID that affects a product developed by Wordpress Social Login Project — matched by CVE ID, not by vendor name.