← WordPress Vulnerabilities
WordPress security by component

Super Socializer

Super Socializer adds social sharing, social comments, and social login features to WordPress websites.

Super Socializer (super-socializer) is a WordPress plugin with 10 published CVE records in this archive. The latest tracked vulnerability was published Aug 06, 2026; the highest published CVSS base score is 8.8.

Plugin slug: super-socializer

CVE-2026-65544: Super Socializer permits unauthenticated cross-site scripting

An unauthenticated visitor can submit attacker-controlled content that Super Socializer 7.14.5 and earlier renders without sufficient output encoding.

PublishedAug 06, 2026
Known safe version> 7.14.5
Published vulnerabilities for super-socializer
Safe version
Aug 06, 2026 CVE-2026-65544
Super Socializer permits unauthenticated cross-site scripting
An unauthenticated visitor can submit attacker-controlled content that Super Socializer 7.14.5 and earlier renders without sufficient output encoding.
> 7.14.5
CVE7.1
NVDPending
Aug 06, 2026 CVE-2026-65542
Unauthenticated broken authentication in Super Socializer
Super Socializer through 7.14.5 contains an authentication flaw reachable without a WordPress account.
> 7.14.5
CVE8.8
NVDPending
Jul 08, 2026 CVE-2026-11798
Social Share, Social Login and Social Comments Plugin – Super Socializer: Cross-site scripting
Social Share, Social Login and Social Comments Plugin – Super Socializer is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 7.14.5.
See mitigation notes
CVE6.1
NVDPending
Jan 21, 2025 CVE-2024-13230
Social Share, Social Login and Social Comments Plugin – Super Socializer: SQL injection
Social Share, Social Login and Social Comments Plugin – Super Socializer is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE5.3
NVDPending
Dec 13, 2024 CVE-2023-41802
Super Socializer: A security weakness
Super Socializer is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 06, 2024 CVE-2024-9946
Social Share, Social Login and Social Comments Plugin – Super Socializer: Privilege escalation or authentication bypass
Social Share, Social Login and Social Comments Plugin – Super Socializer is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVD8.1
Apr 15, 2024 CVE-2024-2836
Social Share, Social Login and Social Comments Plugin: Cross-site scripting
Social Share, Social Login and Social Comments Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jun 20, 2023 CVE-2023-35882
Super Socializer: Cross-site scripting
Super Socializer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jan 16, 2023 CVE-2022-4484
Social Share, Social Login and Social Comments Plugin: Cross-site scripting
Social Share, Social Login and Social Comments Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Apr 11, 2022 CVE-2021-24987
Social Share, Social Login and Social Comments Plugin: Cross-site scripting
Social Share, Social Login and Social Comments Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1