Stored Cross-Site Scripting Vulnerability in Wp Social Login Plugin by WordPress
CVE-2026-97344
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-97344?
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to stored cross-site scripting via the Avatar Alt Attribute due to inadequate input sanitization and output escaping. This vulnerability affects all versions prior to 3.2.1. Authenticated attackers, with subscriber-level privileges and above, can exploit this flaw to inject malicious scripts into pages, which execute when other users access the compromised pages. The attack requires a two-step process: first, the attacker must invoke the nonce-only dismiss_ajax_call endpoint, which is accessible to subscribers, to set the xs_social_profile_image meta flag on their account. This action activates the unescaped image output branch in the xs_social_get_avatar function. Secondly, the attacker can then modify their display name to include a script payload that remains unaltered by core's ENT_NOQUOTES handling.
Affected Version(s)
Wp Social Login and Register Social Counter 0 <= 3.2.1