← WordPress Vulnerabilities
WordPress security by component

WooCommerce Social Login

WooCommerce Social Login is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Apr 16, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: woocommerce-social-login

CVE-2025-39472: WooCommerce Social Login: Cross-site request forgery

WooCommerce Social Login is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedApr 16, 2025
Safe version guidanceSee mitigation notes
Safe version
Apr 16, 2025 CVE-2025-39472
WooCommerce Social Login: Cross-site request forgery
WooCommerce Social Login is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Nov 05, 2024 CVE-2024-10114
WooCommerce - Social Login: Privilege escalation or authentication bypass
WooCommerce - Social Login is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVDPending
Aug 12, 2024 CVE-2024-7503
WooCommerce - Social Login: Privilege escalation or authentication bypass
WooCommerce - Social Login is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Jul 20, 2024 CVE-2024-6637
WooCommerce - Social Login: Privilege escalation or authentication bypass
WooCommerce - Social Login is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.3
NVDPending
Jul 20, 2024 CVE-2024-6636
WooCommerce - Social Login: A security weakness
WooCommerce - Social Login is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVDPending
Jul 20, 2024 CVE-2024-6635
WooCommerce - Social Login: Privilege escalation or authentication bypass
WooCommerce - Social Login is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.3
NVDPending
Jun 15, 2024 CVE-2024-5871
WooCommerce - Social Login: Code execution
WooCommerce - Social Login is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Jun 15, 2024 CVE-2024-5868
WooCommerce - Social Login: A security weakness
WooCommerce - Social Login is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD5.3