Impact
The vulnerability allows authenticated users with subscriber or higher privileges to inject arbitrary JavaScript into a page by exploiting an unescaped ‘alt’ attribute of a user avatar. The exploit chains two actions: first, the attacker uses a plugin Ajax endpoint that accepts a nonce to set a meta flag enabling the unescaped avatar output; then the attacker changes their display name to a script payload that bypasses WordPress’ ENT_NOQUOTES escaping. When the avatar image is rendered on a site page, the injected code runs in the browser of any visitor.
Affected Systems
Wp Social Login and Register Social Counter, released by roxnor, is affected in all versions up to and including 3.2.1. The flaw impacts any WordPress installation that has the plugin enabled and has users with subscriber‑level or higher capability.
Risk and Exploitability
The vulnerability scores a CVSS 6.4, indicating medium severity. EPSS is not available, and the issue is not listed in CISA’s KEV catalog. An attacker must first authenticate as a subscriber or higher, call the Ajax endpoint to flip the meta flag, and then craft a malicious display name. If successful, the attacker can achieve client‑side script execution for all users who view pages containing the avatar image. The limited access requirement reduces the likelihood of exploitation, but the impact on confidentiality and integrity of affected users’ sessions can be significant.
OpenCVE Enrichment