Junglewise Threat Intelligence

CVE-2026-65561: miniOrange WordPress Social Login and Register XSS in Contributor role

CVE-2026-65561 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Executive brief

The WordPress Social Login and Register plugin, which allows users to sign into websites using social media accounts, contains a security flaw that could allow users with 'Contributor' permissions to inject malicious scripts. If a site administrator views the affected area, these scripts could execute, potentially leading to unauthorized actions or the redirection of visitors to malicious websites. This risk is primarily relevant to sites that allow multiple users to contribute content.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the miniOrange WordPress Social Login and Register plugin (versions <= 7.8.0) due to improper neutralization of input during web page generation (CWE-79). An attacker with 'Contributor' level privileges can inject malicious JavaScript payloads into the application. Because the vulnerability is 'Stored' and has a 'Changed' scope (S:C), the script executes in the browser of other users, typically administrators, when they interact with the affected plugin settings or content. This requires some level of user interaction from the victim. The issue is resolved in version 7.8.1.

Affected products

  • miniOrange WordPress Social Login and Register <= 7.8.0

Timeline

  • 2026-07-13: other: Reported by researcher Ananda Dhakal
  • 2026-07-24: advisory: Patchstack advisory published
  • 2026-07-27: disclosed: CVE published to NVD dataset
  • 7.8.1: patched: Vulnerability fixed in version 7.8.1

References

Related threats