Stored Cross-Site Scripting Vulnerability in Wp Social Login Plugin by WordPress
CVE-2026-97344

6.4MEDIUM

What is CVE-2026-97344?

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to stored cross-site scripting via the Avatar Alt Attribute due to inadequate input sanitization and output escaping. This vulnerability affects all versions prior to 3.2.1. Authenticated attackers, with subscriber-level privileges and above, can exploit this flaw to inject malicious scripts into pages, which execute when other users access the compromised pages. The attack requires a two-step process: first, the attacker must invoke the nonce-only dismiss_ajax_call endpoint, which is accessible to subscribers, to set the xs_social_profile_image meta flag on their account. This action activates the unescaped image output branch in the xs_social_get_avatar function. Secondly, the attacker can then modify their display name to include a script payload that remains unaltered by core's ENT_NOQUOTES handling.

Affected Version(s)

Wp Social Login and Register Social Counter 0 <= 3.2.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman
.