PLUGIN SECURITY

Is Wp Social safe?

Wp social lets you add social login, social counter, and social share buttons of different styles to your WordPress website.

What this plugin does

  • Slug: wp-social
  • Author: Roxnor
  • 80000+ active installs
  • 92/100 rating (67 reviews on wordpress.org)
  • 1010429 all-time downloads
  • On WordPress.org since 2010-08-19

socialsocial countersocial loginsocial shareWordPress Social login and register

Maintenance status

  • Last updated: 2026-05-21 6:47am GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 7.4+

Known vulnerabilities

5 known CVEs on file for Wp Social.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13620 Wp Social Login and Register Social Counter [wp-social] < 3.1.4 Missing Authorization Medium 5.3 < 3.1.4 3.1.4 2025-12-04
CVE-2024-9501 Wp Social Login and Register Social Counter [wp-social] < 3.0.8 Authentication Bypass Using an Alternate Path or Channel Critical 9.8 < 3.0.8 3.0.8 2024-10-25
CVE-2024-1763 Wp Social Login and Register Social Counter [wp-social] < 3.0.1 Missing Authorization Medium 5.3 < 3.0.1 3.0.1 2024-02-29
CVE-2022-47160 Wp Social Login and Register Social Counter [wp-social] < 2.0 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 2.0 2.0 2022-12-14
CVE-2025-1506 Wp Social Login and Register Social Counter [wp-social] < 3.1.1 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.1.1 3.1.1 0000-00-00

CVE-2025-13620

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback set to __return_true and lacking capability or nonce validation in their handlers. This makes it possible for unauthenticated attackers to clear or overwrite the social counter cache via crafted REST requests.

Source: CVE.org

CVE-2024-9501

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

Source: CVE.org

CVE-2024-1763

Update the WordPress Wp Social plugin to the latest available version (at least 3.0.1). Krzysztof Zając discovered and reported this Broken Access Control vulnerability in WordPress Wp Social Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.0.1. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2022-47160

The Wp Social plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.9.0. This is due to missing capability checks on the 'export_users_content_csv' function. This makes it possible for authenticated attackers with minimal permissions such as subscribers to export user content such as user logins and passwords of various social media providers.

Source: Wordfence

CVE-2025-1506

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function. This makes it possible for unauthenticated attackers to update social login provider settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.