Description
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The miniOrange WordPress Social Login and Register plugin contains a flaw that allows malicious script code to be injected and executed in visitors' browsers when the plugin processes or displays certain user‑supplied data. This is a classic Cross‑Site Scripting weakness (CWE‑79) that can lead to cookie theft, session hijacking, defacement, or other client‑side attacks while giving an attacker full control over the victim’s browser environment.

Affected Systems

The vulnerability affects installations of the miniOrange WordPress Social Login and Register plugin with versions 7.8.0 or earlier that are enabled on WordPress sites. Any site that uses the plugin to provide social login or registration functionality is potentially exposed if the plugin is active and receives user input from public pages.

Risk and Exploitability

The vulnerability is rated with a CVSS score of 6.5, indicating medium severity. The EPSS score is reported as less than 1%, suggesting a low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is submitting crafted input through the plugin’s social login or registration interfaces; based on the description, it is inferred that an attacker can trigger the flaw by injecting JavaScript payloads that the plugin renders unescaped. No confirmed live exploitation is documented, so the risk primarily depends on the plugin’s exposure to internet traffic and the volume of user interactions.

Generated by OpenCVE AI on August 3, 2026 at 17:29 UTC.

Remediation

Vendor Solution

Update the WordPress WordPress Social Login and Register Plugin to the latest available version (at least 7.8.1).


OpenCVE Recommended Actions

  • Upgrade the miniOrange WordPress Social Login and Register plugin to version 7.8.1 or later to apply the vendor‑supplied fix.
  • If an upgrade cannot be performed immediately, temporarily deactivate the plugin or restrict its use on public‑facing pages until the patch is applied.
  • Implement a Content Security Policy that disallows inline scripts and restricts external scripts to mitigate potential XSS impact until the plugin is fully patched.

Generated by OpenCVE AI on August 3, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Miniorange
Miniorange wordpress Social Login And Register
Wordpress
Wordpress wordpress
Vendors & Products Miniorange
Miniorange wordpress Social Login And Register
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
Title WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Miniorange Wordpress Social Login And Register
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:07:44.552Z

Reserved: 2026-07-22T08:54:23.962Z

Link: CVE-2026-65561

cve-icon Vulnrichment

Updated: 2026-07-27T16:07:39.661Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:09.357

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-65561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')