Extension WordPress

Vulnérabilités Wp Social Login and Register Social Counter

Cette page rassemble les failles publiées pour Wp Social Login and Register Social Counter, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
1Critiques
5Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Wp Social Login and Register Social Counter

5 fiches

CVE-2025-13620 Moyenne · 5,3
Wp Social Login and Register Social Counter

Wp Social Login and Register Social Counter <= 3.1.3 – Missing Authorization in Cache REST Endpoints to Social Counter Tampering

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback…

Versions affectées

*-3.1.3

Correctif

3.1.4

Publication

04/12/2025

CVE-2025-1506 Moyenne · 4,3
Wp Social Login and Register Social Counter

Wp Social Login and Register Social Counter <= 3.1.0 – Cross-Site Request Forgery to Settings Update

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function.…

Versions affectées

*-3.1.0

Correctif

3.1.1

Publication

27/02/2025

CVE-2024-9501 Critique · 9,8
Wp Social Login and Register Social Counter

Wp Social Login and Register Social Counter <= 3.0.7 – Authentication Bypass via WordPress.com OAuth provider

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social…

Versions affectées

*-3.0.7

Correctif

3.0.8

Publication

26/10/2024

CVE-2024-1763 Moyenne · 6,5
Wp Social Login and Register Social Counter

Wp Social Login and Register Social Counter <= 3.0.0 – Missing Authorization to Unauthenticated Social Login/Share Status Update

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0.…

Versions affectées

*-3.0.0

Correctif

3.0.1

Publication

29/02/2024

CVE-2022-47160 Moyenne · 6,8
Wp Social Login and Register Social Counter

Wp Social <= 1.9.0 – Authenticated (Subscriber+) Information Disclosure

The Wp Social plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.9.0. This is due to missing capability checks on the 'export_users_content_csv' function. This makes it possible for authenticated attackers with minimal…

Versions affectées

*-1.9.0

Correctif

2.0

Publication

14/12/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités