← Back

Wordpress Social Login And Register (discord, Google, Twitter, Linkedin)

wordpress_social_login_and_register_(discord,_google,_twitter,_linkedin)

Vendor: Miniorange • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Miniorange
1Wordpress Social Login And Register (discord, Google, Twitter, Linkedin)
Apr 8, 2026
Jun 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on...Show more
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the email address associated with that user. This was partially patched in version 7.6.4 and fully patched in version 7.6.5.Show less
1Miniorange
1Wordpress Social Login And Register (discord, Google, Twitter, Linkedin)
Nov 21, 2024
May 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
1Miniorange
1Wordpress Social Login And Register (discord, Google, Twitter, Linkedin)
Nov 21, 2024
Apr 25, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.