VYPR

Super Socializer

by WordPress

CVEs (7)

  • CVE-2026-65542HigAug 6, 2026
    risk 0.57cvss 8.8epss 0.00

    Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.

  • CVE-2026-65544HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.

  • CVE-2024-9946HigNov 6, 2024
    risk 0.46cvss 8.1epss 0.01

    The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user being returned by the social login…

  • CVE-2023-35882MedJun 20, 2023
    risk 0.42cvss 6.5epss 0.00

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor Super Socializer plugin <= 7.13.52 versions.

  • CVE-2023-41802MedDec 13, 2024
    risk 0.28cvss 4.3epss 0.01

    Missing Authorization vulnerability in Team Heateor Super Socializer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Socializer: from n/a through 7.13.54.

  • CVE-2024-13230MedJan 21, 2025
    risk 0.27cvss 5.3epss 0.00

    The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter in all versions up to, and including, 7.14 due to insufficient escaping on the user supplied…

  • CVE-2026-11798MedJul 8, 2026
    risk 0.00cvss 6.1epss 0.00

    The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input sanitization and…