Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.4) | 0.19% | — | Wpmet WP Social Login AND Register Social CounterAI | 3/10/2026 | 3/10/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | |
| Aplazada | Crítica (9.8) | 0.63% | — | Soclever Social Login Sharing Buttons With AnalyticsAI | 22/8/2026 | 26/8/2026 | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators.… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. | |
| Aplazada | Alta (8.1) | 0.75% | — | Ventraconnect Social Login Passwordless LoginAI | 12/8/2026 | 12/8/2026 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Wpwebelite Woocommerce Social LoginAI | 2/8/2026 | 12/8/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or… | |
| Aplazada | Alta (8.1) | 0.38% | — | Miniorange Social Login AND RegisterAI | 29/7/2026 | 30/7/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any… | |
| Aplazada | Media (6.5) | 0.22% | — | Wordpress Social Login AND RegisterAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | |
| Aplazada | Alta (8.1) | 0.38% | — | Social Login Passkeys Magic Link Email OTPAI | 20/7/2026 | 21/7/2026 | The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email… | |
| Aplazada | Crítica (9.8) | 0.89% | — | Miniorange Social Login AND RegisterAI | 10/7/2026 | 13/7/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_field' POST… | |
| Aplazada | Alta (8.1) | 0.19% | — | Heateor Social LoginAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Directorist Social LoginAI | 27/4/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4. | |
| Aplazada | Media (6.6) | 0.48% | — | Miniorange Wordpress Social Login AND RegisterAI | 30/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <= 7.7.0. | |
| Aplazada | Media (5.4) | 0.13% | — | Heateor Social LoginAI | 30/12/2025 | 5/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Heateor Support Heateor Social Login heateor-social-login allows Cross Site Request Forgery.This issue affects Heateor Social Login: from n/a through <= 1.1.39. | |
| Aplazada | Media (5.3) | 0.37% | — | Wpmet WP Social Login AND Register Social CounterAI | 5/12/2025 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback… | |
| Aplazada | Media (4.3) | 0.15% | — | Nextend Social Login AND RegisterAI | 28/11/2025 | 30/9/2026 | The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is due to missing or incorrect nonce validation on the 'unlinkUser' function. This makes it possible for unauthenticated attackers to unlink the user's social login… | |
| Aplazada | Media (6.4) | 0.29% | — | Quick Social LoginAI | 15/10/2025 | 17/6/2026 | The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' shortcode in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.24% | — | Heateor Login Social LoginAI | 10/9/2025 | 17/6/2026 | The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Heateor_Facebook_Login' shortcode in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (8.1) | 0.64% | — | Miniorange Wordpress Social Login AND RegisterAI | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <= 7.6.10. | |
| Modificada | Alta (8.8) | 0.17% | — | Wpwebelite Woocommerce Social Login | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a through < 2.8.3. | |
| Analizada | Crítica (9.8) | 0.47% | — | Miniorange Social Login | 8/3/2025 | 17/6/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for… | |
| Analizada | Media (4.3) | 0.20% | — | Wpmet WP Social Login AND Register Social Counter | 28/2/2025 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function. This makes it possible for unauthenticated attackers to update… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Nextend Social Login PROAI | 7/2/2025 | 17/6/2026 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.3) | 0.76% | — | Miniorange Wordpress Social Login AND RegisterAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.0. | |
| Aplazada | Baja (3.5) | 0.44% | — | Miniorange Wordpress Social LoginAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.5.14. |