Extension WordPress
Vulnérabilités Wp Social Login and Register Social Counter
Cette page rassemble les failles publiées pour Wp Social Login and Register Social Counter, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Wp Social Login and Register Social Counter
5 fiches
Wp Social Login and Register Social Counter <= 3.1.3 – Missing Authorization in Cache REST Endpoints to Social Counter Tampering
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback…
*-3.1.3
3.1.4
04/12/2025
Wp Social Login and Register Social Counter <= 3.1.0 – Cross-Site Request Forgery to Settings Update
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function.…
*-3.1.0
3.1.1
27/02/2025
Wp Social Login and Register Social Counter <= 3.0.7 – Authentication Bypass via WordPress.com OAuth provider
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social…
*-3.0.7
3.0.8
26/10/2024
Wp Social Login and Register Social Counter <= 3.0.0 – Missing Authorization to Unauthenticated Social Login/Share Status Update
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0.…
*-3.0.0
3.0.1
29/02/2024
Wp Social <= 1.9.0 – Authenticated (Subscriber+) Information Disclosure
The Wp Social plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.9.0. This is due to missing capability checks on the 'export_users_content_csv' function. This makes it possible for authenticated attackers with minimal…
*-1.9.0
2.0
14/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.