CVE · Medium

CVE-2022-47160 — Wp Social Login and Register Social Counter [wp-social] < 2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-47160 Wp Social Login and Register Social Counter [wp-social] < 2.0 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 2.0 2.0 2022-12-14

CVE-2022-47160

The Wp Social Login and Register Social Counter plugin for WordPress through version 1.9.0 allows authenticated users with subscriber-level privileges to export sensitive user information including login credentials and passwords for connected social media accounts. The vulnerability exists because the export_users_content_csv function lacks proper capability checks, enabling low-privileged attackers to bypass authorization controls and access confidential data they should not be able to retrieve.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.