Description
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
Published: 2026-08-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated broken authentication flaw exists in versions of Super Socializer up to 7.14.5, allowing an attacker to bypass normal login controls and obtain full administrative privileges. This vulnerability falls under the CWE-288 category and could lead to compromise of the entire WordPress site, including content, user data, and configuration settings. The potential impact includes data theft, site defacement, and further lateral movement within the hosting environment.

Affected Systems

The affected product is Super Socializer, developed by Rajat Varlani, a WordPress plugin used for social login and sharing features. All releases from the first version through 7.14.5 are vulnerable. Users running any of these versions should verify the installed version number and consider an immediate update.

Risk and Exploitability

With a CVSS score of 8.8, this vulnerability is classified as high severity. EPSS information is not available, so the exploitation probability cannot be quantified; however, the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote exploitation via web requests to the plugin's authentication endpoints, as the flaw allows unauthenticated access. An attacker would need only network access to the WordPress site to leverage the flaw, making it broadly exploitable.

Generated by OpenCVE AI on August 6, 2026 at 15:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Super Socializer to a version newer than 7.14.5
  • If upgrading is temporarily infeasible, disable or restrict the plugin by removing it from all active themes or via plugin management tools
  • Enforce strong login controls such as two‑factor authentication and limit administrative account access

Generated by OpenCVE AI on August 6, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
Title WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:53:27.777Z

Reserved: 2026-07-22T08:54:12.816Z

Link: CVE-2026-65542

cve-icon Vulnrichment

Updated: 2026-08-06T14:53:23.799Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:00:06Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel