Executive brief
WordPress Social Login and Register is a plugin that enables users to log in and register using social media accounts. Unauthenticated attackers can inject malicious scripts into websites using this plugin, allowing them to steal visitor data, hijack user accounts, or redirect traffic to malicious sites. Affected websites should update immediately to patch the vulnerability.
Technical details
This is a Cross Site Scripting (XSS) vulnerability affecting WordPress Social Login and Register plugin versions up to 7.8.2. The vulnerability is unauthenticated and does not require special privileges to initiate, though successful exploitation typically requires user interaction such as clicking a malicious link or visiting a crafted page. An attacker can inject arbitrary JavaScript code that executes in the context of affected users' browsers, potentially leading to session hijacking, credential theft, or malware distribution. The vulnerability is fixed in version 7.9.0 and later.
Affected products
- miniOrange Social Login and Register <=7.8.2
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Version 7.9.0 released
- 2026-08-31: advisory