PLUGIN SECURITY

Is Nextend Facebook Connect safe?

One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.

What this plugin does

  • Slug: nextend-facebook-connect
  • Author: Nextendweb
  • 200000+ active installs
  • 98/100 rating (446 reviews on wordpress.org)
  • 7965503 all-time downloads
  • On WordPress.org since 2012-09-25

facebookgooglesocial logintwitterx

Maintenance status

  • Latest known version: 3.1.26
  • Last updated: 2026-07-28 8:27am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

5 known CVEs on file for Nextend Facebook Connect. Reported between 2014 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13737 Nextend Social Login and Register [nextend-facebook-connect] < 3.1.22 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.1.22 3.1.22 2025-11-27 ✓ fixed in latest
CVE-2025-58031 Nextend Social Login and Register [nextend-facebook-connect] < 3.1.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.1.20 3.1.20 2025-09-22 ✓ fixed in latest
CVE-2024-1775 Nextend Social Login and Register [nextend-facebook-connect] < 3.1.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.1.13 3.1.13 2024-03-01 ✓ fixed in latest
Nextend Social Login and Register [nextend-facebook-connect] < 1.5.9 Unknown < 1.5.9 1.5.9 2016-03-15 ✓ fixed in latest
CVE-2015-4413 Nextend Social Login and Register [nextend-facebook-connect] < 1.5.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 1.5.6 1.5.6 2015-06-24 ✓ fixed in latest
CVE-2014-8800 Nextend Social Login and Register [nextend-facebook-connect] < 1.5.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 1.5.1 1.5.1 2014-02-12 ✓ fixed in latest
Nextend Social Login and Register [nextend-facebook-connect] < 1.5.8 Unknown < 1.5.8 1.5.8 ✓ fixed in latest
Nextend Facebook Connect <= 1.5.7 - Cross-Site Request Forgery (CSRF) Unknown < 1.5.8 1.5.8 ✓ fixed in latest

How to fix it

Keep Nextend Facebook Connect updated — 3.1.26 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.