← WordPress Vulnerabilities
WordPress security by component

miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon

miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Mar 08, 2025; the highest CVE/CNA score is 8.1.

Plugin slug: social-login

CVE-2024-11087: miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon: Privilege escalation or authentication bypass

miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.

PublishedMar 08, 2025
Safe version guidanceSee mitigation notes
Safe version
Mar 08, 2025 CVE-2024-11087
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon: Privilege escalation or authentication bypass
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVD9.8
Nov 06, 2024 CVE-2024-10020
Heateor Social Login: Privilege escalation or authentication bypass
Heateor Social Login is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVD8.1