PLUGIN SECURITY
Is Nextend Facebook Connect safe?
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
What this plugin does
- Slug:
nextend-facebook-connect - Author: Nextendweb
- 200000+ active installs
- 98/100 rating (446 reviews on wordpress.org)
- 7965503 all-time downloads
- On WordPress.org since 2012-09-25
facebookgooglesocial logintwitterx
Maintenance status
- Latest known version: 3.1.26
- Last updated: 2026-07-28 8:27am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
5 known CVEs on file for Nextend Facebook Connect. Reported between 2014 and 2025.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-13737 | Nextend Social Login and Register [nextend-facebook-connect] < 3.1.22 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 3.1.22 | 3.1.22 | 2025-11-27 | ✓ fixed in latest |
| CVE-2025-58031 | Nextend Social Login and Register [nextend-facebook-connect] < 3.1.20 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.1.20 | 3.1.20 | 2025-09-22 | ✓ fixed in latest |
| CVE-2024-1775 | Nextend Social Login and Register [nextend-facebook-connect] < 3.1.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.1.13 | 3.1.13 | 2024-03-01 | ✓ fixed in latest |
| — | Nextend Social Login and Register [nextend-facebook-connect] < 1.5.9 | — | Unknown | < 1.5.9 | 1.5.9 | 2016-03-15 | ✓ fixed in latest |
| CVE-2015-4413 | Nextend Social Login and Register [nextend-facebook-connect] < 1.5.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 1.5.6 | 1.5.6 | 2015-06-24 | ✓ fixed in latest |
| CVE-2014-8800 | Nextend Social Login and Register [nextend-facebook-connect] < 1.5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 1.5.1 | 1.5.1 | 2014-02-12 | ✓ fixed in latest |
| — | Nextend Social Login and Register [nextend-facebook-connect] < 1.5.8 | — | Unknown | < 1.5.8 | 1.5.8 | — | ✓ fixed in latest |
| — | Nextend Facebook Connect <= 1.5.7 - Cross-Site Request Forgery (CSRF) | — | Unknown | < 1.5.8 | 1.5.8 | — | ✓ fixed in latest |
How to fix it
Keep Nextend Facebook Connect updated — 3.1.26 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Site Kit by Google – Analytics, Search Console, AdSense, Speed — 5000000+ active installs — 84/100 (1009)
- Widgets for Google Reviews — 900000+ active installs — 98/100 (2630) — max PHP 8.4
- Google for WooCommerce — 800000+ active installs — 54/100 (266)
- Meta for WooCommerce — 400000+ active installs — 42/100 (479) — max PHP 8.4
- Meta pixel for WordPress — 400000+ active installs — 54/100 (164)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.