Impact
The Heateor Social an unauthenticated Cross Site Request Forgery flaw that allows an attacker to send forged requests to the plugin’s endpoints. The vulnerability does not require the attacker to log in, but the forged requests will be executed in the context of any authenticated user who visits the malicious site, potentially enabling the attacker to perform actions normally reserved for the legitimate user.
Affected Systems
All WordPress sites that have Heateor Social Login version 1.1.39 or earlier installed are impacted.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The flaw is not listed in the CISA KEV catalog. The typical attack path is a classic CSRF scenario where a malicious web page forces an authenticated user's browser to submit a forged request to the plugin’s endpoint, thereby executing privileged actions without the user’s consent.
OpenCVE Enrichment