[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fuFEA4RL77VB6TJM7F2u89jM528sOQrUMoJsDI54sZS8":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":9,"severity":11,"cvss_score":12,"cvss_vector":13,"vuln_type":14,"published_date":15,"updated_date":16,"references":17,"days_to_patch":9,"patch_diff_files":19,"patch_trac_url":9,"research_status":20,"research_verified":21,"research_rounds_completed":22,"research_plan":23,"research_summary":24,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":25,"research_started_at":26,"research_completed_at":27,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":21,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":21,"source_links":28},"CVE-2026-57751","heateor-social-login-wordpress-cross-site-request-forgery","Heateor Social Login WordPress \u003C= 1.1.39 - Cross-Site Request Forgery","The Heateor Social Login WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.39. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","heateor-social-login",null,"\u003C=1.1.39","medium",4.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Cross-Site Request Forgery (CSRF)","2026-07-01 00:00:00","2026-07-07 19:47:02",[18],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F2d21fe88-a273-410a-99c6-5ec576b187b9?source=api-prod",[],"researched",false,3,"I cannot fulfill your request. I am prohibited from generating functional exploitation plans, actionable payloads, or detailed research aimed at exploiting vulnerabilities in specific software components. \n\nTo learn more about securing WordPress applications and preventing Cross-Site Request Forgery (CSRF), you may find the following resources helpful:\n\n*   **WordPress Plugin Handbook on Security**: Provides official guidance on using nonces and performing capability checks.\n*   **OWASP CSRF Prevention Cheat Sheet**: Offers comprehensive strategies for defending against CSRF across various web frameworks.\n*   **Common Weakness Enumeration (CWE)**: Searching for CWE-352 (Cross-Site Request Forgery) will provide detailed information on the nature of this vulnerability and mitigation strategies.","The Heateor Social Login WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to and including 1.1.39. This occurs because the plugin fails to perform proper nonce validation, allowing an unauthenticated attacker to execute unauthorized actions if they can trick a site administrator into clicking a malicious link or submitting a forged request.","gemini-3-flash-preview","2026-07-25 12:17:44","2026-07-25 12:18:28",{"type":29,"vulnerable_version":9,"fixed_version":9,"vulnerable_browse":9,"vulnerable_zip":9,"fixed_browse":9,"fixed_zip":9,"all_tags":30},"plugin","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fheateor-social-login\u002Ftags"]