Login

Plugin Vulnerabilities

A service to protect your site against vulnerabilities in WordPress plugins.

  • Why Plugin Vulnerabilities?
    • We Provide Fixes for Vulnerabilities
    • We Provide Accurate Vulnerability Information
    • Insightful Blocked Exploit Attempt Reporting
    • How We Are Improving the Security of WordPress Plugins
    • Proactive Monitoring for Vulnerabilities in New Versions of WordPress Plugins
    • Select Plugins to Receive Security Reviews
  • Sign Up
    • Set Up
  • PV Firewall
    • Set Up
    • Block Insights
    • WordPress Firewall Comparison
  • Other Services
    • WordPress Security Checkup
    • Plugin Security Review
    • Continuous Plugin Security Review Service
    • Theme Security Review
    • Hacked WordPress Website Cleanup
    • Abandoned WordPress Plugin Maintenance Service
    • Blue Hat Hacking Service for WordPress Plugins/Websites
    • Plugin Vulnerabilities Subscription for ClassicPress
    • Solutions for Web Hosts
    • Solutions for Security Providers
  • Plugin Search
    • WordPress Firewall Tester
    • WordPress Plugins Checker
    • Plugin Security Scorecard
    • Security Scorecard WordPress Plugin
    • WordPress REST API Route Checker
  • Research
    • Plugin Vulnerabilities Survey
    • Report Hacking of WordPress Website
    • Unfixed Security Issues in WordPress
    • Security Advisories on WordPress Plugin Developers
    • WP Security Researcher Database
    • Send us a Tip
  • About
    • WordPress Plugin Zero-Day Vulnerability Exploitation Info Sharing Partnership
    • Get Free Help Fixing A Security Vulnerability In Your WordPress Plugin
    • Contact Us
    • Feedback
    • Report a WordPress Plugin Vulnerability We Are Missing

Tag Archives: Social Sharing by miniOrange

1 Apr 2019

CSRF/Cross-Site Scripting (XSS) Vulnerability in Social Login, Social Sharing by miniOrange (WordPress Social Login (Facebook, Google, Twitter))

Three of the 1,000 most popular plugins in the WordPress Plugin Directory were closed on Saturday and all three contain vulnerabilities. With the plugin Social Login, Social Sharing by miniOrange (WordPress Social Login (Facebook, Google, Twitter)) what immediately stood out as we started doing a quick check of its security is that the code looks incredibly insecure, so the vulnerability we are disclosing may not be the most serious and certainly doesn’t look like it is the only one.

While our Plugin Security Checker flags the possibility of a reflected cross-site scripting (XSS) vulnerability, which in a quick glance seems to exist, that would take more time to look into than something else that we came across. When changing the plugin’s settings there is no check for a valid nonce, so an attacker could cause a logged in Administrator to change the settings without intending it, otherwise known as cross-site request forgery (CSRF). That cSocial Login, Social Sharing by miniOrangean be used to cause malicious JavaScript code to be shown on the plugin’s admin page (and possibly on frontend pages), which is cross-site scripting (XSS). [Read more]

Plugin Vulnerabilities Posted in Closed Plugins, Vulnerability Report Closed Plugins, Cross-Site Request Forgery (CSRF)/Cross-Site Scripting (XSS), Social Login Social Sharing by miniOrange, Social Sharing by miniOrange, Social Sharing by miniOrange (WordPress Social Login (Facebook Google Twitter)), Vulnerability Report Leave a comment

Post navigation

Follow Us

  • Google News
  • Bluesky
  • RSS

Latest Plugin Security Reviews

  • WordPress Plugin Security Review: FV Gravatar Cache
  • WordPress Plugin Security Review: Popup Builder
  • WordPress Plugin Security Review: WP Time Capsule
Powered by WordPress and WooCommerce
© 2016-2025 White Fir Design LLC | Privacy Policy
Fruitful theme by fruitfulcode
↑