CVE · Medium

CVE-2025-13737 — Nextend Social Login and Register [nextend-facebook-connect] < 3.1.22

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13737 Nextend Social Login and Register [nextend-facebook-connect] < 3.1.22 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.1.22 3.1.22 2025-11-27

CVE-2025-13737

The Nextend Social Login and Register plugin for WordPress, up to version 3.1.21, is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in the 'unlinkUser' function. Attackers can exploit this by tricking an administrator into executing a forged request that unlinks the user's social login, assuming they have the ability to deceive the site admin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.