Login

Plugin Vulnerabilities

A service to protect your site against vulnerabilities in WordPress plugins.

  • Why Plugin Vulnerabilities?
    • We Provide Fixes for Vulnerabilities
    • We Provide Accurate Vulnerability Information
    • Insightful Blocked Exploit Attempt Reporting
    • How We Are Improving the Security of WordPress Plugins
    • Proactive Monitoring for Vulnerabilities in New Versions of WordPress Plugins
    • Select Plugins to Receive Security Reviews
  • Sign Up
    • Set Up
  • PV Firewall
    • Set Up
    • Block Insights
    • WordPress Firewall Comparison
  • Other Services
    • WordPress Security Checkup
    • Plugin Security Review
    • Continuous Plugin Security Review Service
    • Theme Security Review
    • Hacked WordPress Website Cleanup
    • Abandoned WordPress Plugin Maintenance Service
    • Blue Hat Hacking Service for WordPress Plugins/Websites
    • Plugin Vulnerabilities Subscription for ClassicPress
    • Solutions for Web Hosts
    • Solutions for Security Providers
  • Plugin Search
    • WordPress Firewall Tester
    • WordPress Plugins Checker
    • Plugin Security Scorecard
    • Security Scorecard WordPress Plugin
    • WordPress REST API Route Checker
  • Research
    • Plugin Vulnerabilities Survey
    • Report Hacking of WordPress Website
    • Unfixed Security Issues in WordPress
    • Security Advisories on WordPress Plugin Developers
    • WP Security Researcher Database
    • Send us a Tip
  • About
    • WordPress Plugin Zero-Day Vulnerability Exploitation Info Sharing Partnership
    • Get Free Help Fixing A Security Vulnerability In Your WordPress Plugin
    • Contact Us
    • Feedback
    • Report a WordPress Plugin Vulnerability We Are Missing

Tag Archives: Social Login Social Sharing by miniOrange

5 Apr 2019

Closures of Very Popular WordPress Plugins, Week of April 5

While we already are far ahead of other companies in keeping up with vulnerabilities in WordPress plugins (amazingly that isn’t an exaggeration), in looking in to how we could get even better we noticed that in a recent instance were a vulnerability was exploited in a plugin, we probably could have warned our customers about the vulnerability even sooner if we had looked at the plugin when it was first closed on the Plugin Directory instead of when the vulnerability was fixed (though as far as we are aware the exploitation started after we had warned our customers of the fix). So we are now monitoring to see if any of the 1,000 most popular plugins are closed on the Plugin Directory and then seeing if it looks like that was due to a vulnerability.

This week four of those plugins were closed and two of them have been reopened. [Read more]

Plugin Vulnerabilities Posted in Closed Plugins 404page, Closed Plugins, Related Posts, Social Login Social Sharing by miniOrange, Toolset Types, WordPress Social Login (Facebook Google Twitter) Leave a comment
1 Apr 2019

CSRF/Cross-Site Scripting (XSS) Vulnerability in Social Login, Social Sharing by miniOrange (WordPress Social Login (Facebook, Google, Twitter))

Three of the 1,000 most popular plugins in the WordPress Plugin Directory were closed on Saturday and all three contain vulnerabilities. With the plugin Social Login, Social Sharing by miniOrange (WordPress Social Login (Facebook, Google, Twitter)) what immediately stood out as we started doing a quick check of its security is that the code looks incredibly insecure, so the vulnerability we are disclosing may not be the most serious and certainly doesn’t look like it is the only one.

While our Plugin Security Checker flags the possibility of a reflected cross-site scripting (XSS) vulnerability, which in a quick glance seems to exist, that would take more time to look into than something else that we came across. When changing the plugin’s settings there is no check for a valid nonce, so an attacker could cause a logged in Administrator to change the settings without intending it, otherwise known as cross-site request forgery (CSRF). That cSocial Login, Social Sharing by miniOrangean be used to cause malicious JavaScript code to be shown on the plugin’s admin page (and possibly on frontend pages), which is cross-site scripting (XSS). [Read more]

Plugin Vulnerabilities Posted in Closed Plugins, Vulnerability Report Closed Plugins, Cross-Site Request Forgery (CSRF)/Cross-Site Scripting (XSS), Social Login Social Sharing by miniOrange, Social Sharing by miniOrange, Social Sharing by miniOrange (WordPress Social Login (Facebook Google Twitter)), Vulnerability Report Leave a comment

Post navigation

Follow Us

  • Google News
  • Bluesky
  • RSS

Latest Plugin Security Reviews

  • WordPress Plugin Security Review: FV Gravatar Cache
  • WordPress Plugin Security Review: Popup Builder
  • WordPress Plugin Security Review: WP Time Capsule
Powered by WordPress and WooCommerce
© 2016-2025 White Fir Design LLC | Privacy Policy
Fruitful theme by fruitfulcode
↑