Description
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to chain two steps: invoking the nonce-only dismiss_ajax_call endpoint (nonce accessible to Subscribers via any wp-admin page) to set the xs_social_profile_image meta flag on their own account, which activates the unescaped img output branch in xs_social_get_avatar, and then setting their display name to a script payload that core's ENT_NOQUOTES handling preserves unescaped.
Published: 2026-10-03
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS (Client‑side Script Execution)
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows authenticated users with subscriber or higher privileges to inject arbitrary JavaScript into a page by exploiting an unescaped ‘alt’ attribute of a user avatar. The exploit chains two actions: first, the attacker uses a plugin Ajax endpoint that accepts a nonce to set a meta flag enabling the unescaped avatar output; then the attacker changes their display name to a script payload that bypasses WordPress’ ENT_NOQUOTES escaping. When the avatar image is rendered on a site page, the injected code runs in the browser of any visitor.

Affected Systems

Wp Social Login and Register Social Counter, released by roxnor, is affected in all versions up to and including 3.2.1. The flaw impacts any WordPress installation that has the plugin enabled and has users with subscriber‑level or higher capability.

Risk and Exploitability

The vulnerability scores a CVSS 6.4, indicating medium severity. EPSS is not available, and the issue is not listed in CISA’s KEV catalog. An attacker must first authenticate as a subscriber or higher, call the Ajax endpoint to flip the meta flag, and then craft a malicious display name. If successful, the attacker can achieve client‑side script execution for all users who view pages containing the avatar image. The limited access requirement reduces the likelihood of exploitation, but the impact on confidentiality and integrity of affected users’ sessions can be significant.

Generated by OpenCVE AI on October 3, 2026 at 06:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Wp Social Login and Register Social Counter plugin to the latest version that removes the unescaped avatar output or uninstall the plugin if no fix is available.
  • For accounts that may have injected payloads, manually delete the xs_social_profile_image meta entry or set it to false, and sanitize any display name fields that contain script code.
  • As a temporary workaround, restrict access to the plugin’s Ajax /dismiss_ajax_call endpoint for subscriber roles, or block it via server‑level rules, to prevent further meta flag manipulation until a patch is applied.

Generated by OpenCVE AI on October 3, 2026 at 06:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to chain two steps: invoking the nonce-only dismiss_ajax_call endpoint (nonce accessible to Subscribers via any wp-admin page) to set the xs_social_profile_image meta flag on their own account, which activates the unescaped img output branch in xs_social_get_avatar, and then setting their display name to a script payload that core's ENT_NOQUOTES handling preserves unescaped.
Title Wp Social Login and Register Social Counter <= 3.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:45.605Z

Reserved: 2026-09-24T12:25:10.497Z

Link: CVE-2026-97344

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:30.007Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:49.707

Modified: 2026-10-03T16:16:49.240

Link: CVE-2026-97344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:45:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')