Stored Cross-Site Scripting Vulnerability in Heateor Login Plugin for WordPress
CVE-2025-9857
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 September 2025
What is CVE-2025-9857?
The Heateor Login – Social Login Plugin for WordPress is susceptible to Stored Cross-Site Scripting due to improper input sanitization and output escaping on the 'Heateor_Facebook_Login' shortcode. This vulnerability affects all versions up to and including 1.1.9. Authenticated attackers with contributor-level permissions can exploit this flaw to inject arbitrary scripts into web pages, which will execute when other users view the compromised content. Proper mitigation strategies, including regular updates and user feedback mechanisms, are essential to safeguard your WordPress site.
Affected Version(s)
Heateor Login – Social Login Plugin * <= 1.1.9