Impact
The miniOrange WordPress Social Login and Register plugin contains a flaw that allows malicious script code to be injected and executed in visitors' browsers when the plugin processes or displays certain user‑supplied data. This is a classic Cross‑Site Scripting weakness (CWE‑79) that can lead to cookie theft, session hijacking, defacement, or other client‑side attacks while giving an attacker full control over the victim’s browser environment.
Affected Systems
The vulnerability affects installations of the miniOrange WordPress Social Login and Register plugin with versions 7.8.0 or earlier that are enabled on WordPress sites. Any site that uses the plugin to provide social login or registration functionality is potentially exposed if the plugin is active and receives user input from public pages.
Risk and Exploitability
The vulnerability is rated with a CVSS score of 6.5, indicating medium severity. The EPSS score is reported as less than 1%, suggesting a low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is submitting crafted input through the plugin’s social login or registration interfaces; based on the description, it is inferred that an attacker can trigger the flaw by injecting JavaScript payloads that the plugin renders unescaped. No confirmed live exploitation is documented, so the risk primarily depends on the plugin’s exposure to internet traffic and the volume of user interactions.
OpenCVE Enrichment