Impact
The flaw is a CSRF vulnerability that allows attackers to trick authenticated visitors of the affected WordPress site into executing unwanted actions through the Heateor Social Login plugin. The plugin, up to version 1.1.39, accepts state‑changing requests without proper token validation, creating a CWE‑352 weakness that could lead to unauthorized account modifications or other unintended operations on the user’s behalf.
Affected Systems
WordPress sites that use the Heateor Social Login plugin with version 1.1.39 or older. The plugin is distributed by Heateor Support under the name Heateor Social Login.
Risk and Exploitability
The CVSS base score of 5.4 and an EPSS score of less than 1 % indicate moderate severity and a very low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog, showing no known widespread attacks. Attackers would need to coerce an authenticated user to submit a crafted request, usually via a malicious page or spoofed form, to benefit from the missing CSRF checks.
OpenCVE Enrichment