← WordPress Vulnerabilities
WordPress security by component

Wp Social Login and Register Social Counter

Wp Social Login and Register Social Counter is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Feb 28, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: wp-social

CVE-2025-1506: Wp Social Login and Register Social Counter: Cross-site request forgery

Wp Social Login and Register Social Counter is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedFeb 28, 2025
Safe version guidanceSee mitigation notes
Safe version
Feb 28, 2025 CVE-2025-1506
Wp Social Login and Register Social Counter: Cross-site request forgery
Wp Social Login and Register Social Counter is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Oct 26, 2024 CVE-2024-9501
Wp Social Login and Register Social Counter: Privilege escalation or authentication bypass
Wp Social Login and Register Social Counter is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Jan 19, 2024 CVE-2022-47160
Wp Social Login and Register Social Counter: A security weakness
Wp Social Login and Register Social Counter is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5