VYPR

Nextend Social Login

by Nextendweb

Source repositories

CVEs (2)

  • CVE-2024-9893CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated…

  • CVE-2024-1775MedMar 2, 2024
    risk 0.28cvss 5.4epss 0.00

    The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting via the ‘error_description’ parameter in all versions up to, and including, 3.1.12 due to insufficient input sanitization and output escaping. This makes…