Junglewise Threat Intelligence

CVE-2026-57751: Heateor Social Login CSRF in WordPress plugin

CVE-2026-57751 · Severity: high · CVSS 8.1 · Published 2026-07-02

Executive brief

Heateor Social Login is a WordPress plugin that allows users to log into websites using their social media accounts. A security flaw in this plugin could allow an attacker to trick a site administrator into performing unintended actions, such as changing site settings or deleting data, by clicking a malicious link. This could lead to unauthorized changes to the website or a compromise of administrative accounts.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Heateor Social Login plugin for WordPress due to missing or insufficient nonce validation on sensitive actions. An unauthenticated remote attacker can exploit this by tricking a logged-in administrator or high-privileged user into visiting a specially crafted webpage or clicking a malicious link. Successful exploitation allows the attacker to execute unauthorized actions in the context of the victim's session, potentially leading to site reconfiguration or data modification. As of the advisory date, no official patch has been released, and users are advised to monitor for updates from the developer.

Affected products

  • Heateor Support Heateor Social Login <= 1.1.39

Timeline

  • 2026-05-29: disclosed: Reported by ParkHyunWoo
  • 2026-07-01: advisory: Published by Patchstack
  • 2026-07-02: other: NVD Published Date

References