Description
Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
Published: 2026-07-02
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Heateor Social an unauthenticated Cross Site Request Forgery flaw that allows an attacker to send forged requests to the plugin’s endpoints. The vulnerability does not require the attacker to log in, but the forged requests will be executed in the context of any authenticated user who visits the malicious site, potentially enabling the attacker to perform actions normally reserved for the legitimate user.

Affected Systems

All WordPress sites that have Heateor Social Login version 1.1.39 or earlier installed are impacted.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The flaw is not listed in the CISA KEV catalog. The typical attack path is a classic CSRF scenario where a malicious web page forces an authenticated user's browser to submit a forged request to the plugin’s endpoint, thereby executing privileged actions without the user’s consent.

Generated by OpenCVE AI on July 21, 2026 at 11:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Heateor Social Login plugin to the latest version that contains the CSRF fix.
  • If the plugin is not required, disable or uninstall it entirely to remove the vulnerability.
  • Apply application‑level CSRF protection or configure a web application firewall to block crafted requests targeting the plugin’s endpoints until an update is applied.

Generated by OpenCVE AI on July 21, 2026 at 11:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Heateor Support
Heateor Support heateor Social Login
Wordpress
Wordpress wordpress
Vendors & Products Heateor Support
Heateor Support heateor Social Login
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
Title WordPress Heateor Social Login plugin <= 1.1.39 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Heateor Support Heateor Social Login
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T13:48:48.500Z

Reserved: 2026-06-25T08:04:34.979Z

Link: CVE-2026-57751

cve-icon Vulnrichment

Updated: 2026-07-02T13:48:42.519Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)