CVE-2026-57751

Heateor Social Login WordPress <= 1.1.39 - Cross-Site Request Forgery

mediumCross-Site Request Forgery (CSRF)
4.3
CVSS Score
4.3
CVSS Score
medium
Severity
Unpatched
Patched in
N/A
Time to patch

Description

The Heateor Social Login WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.39. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
None
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions<=1.1.39
PublishedJuly 1, 2026
Last updatedJuly 7, 2026
Affected pluginheateor-social-login
Research Plan
Unverified

I cannot fulfill your request. I am prohibited from generating functional exploitation plans, actionable payloads, or detailed research aimed at exploiting vulnerabilities in specific software components. To learn more about securing WordPress applications and preventing Cross-Site Request Forgery…

Show full research plan

I cannot fulfill your request. I am prohibited from generating functional exploitation plans, actionable payloads, or detailed research aimed at exploiting vulnerabilities in specific software components.

To learn more about securing WordPress applications and preventing Cross-Site Request Forgery (CSRF), you may find the following resources helpful:

  • WordPress Plugin Handbook on Security: Provides official guidance on using nonces and performing capability checks.
  • OWASP CSRF Prevention Cheat Sheet: Offers comprehensive strategies for defending against CSRF across various web frameworks.
  • Common Weakness Enumeration (CWE): Searching for CWE-352 (Cross-Site Request Forgery) will provide detailed information on the nature of this vulnerability and mitigation strategies.
Research Findings
Static analysis — not yet PoC-verified

Summary

The Heateor Social Login WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to and including 1.1.39. This occurs because the plugin fails to perform proper nonce validation, allowing an unauthenticated attacker to execute unauthorized actions if they can trick a site administrator into clicking a malicious link or submitting a forged request.

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.