CVE-2026-97344
Received Received - Intake

Stored XSS in Wp Social Login and Register Social Counter Plugin

Vulnerability report for CVE-2026-97344, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: Wordfence

Description

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to chain two steps: invoking the nonce-only dismiss_ajax_call endpoint (nonce accessible to Subscribers via any wp-admin page) to set the xs_social_profile_image meta flag on their own account, which activates the unescaped img output branch in xs_social_get_avatar, and then setting their display name to a script payload that core's ENT_NOQUOTES handling preserves unescaped.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_social_login wp_social_login to 3.2.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the Wp Social Login and Register Social Counter WordPress plugin. It allows authenticated attackers with subscriber-level access or higher to inject malicious scripts into web pages. The attack requires two steps: first, exploiting a nonce-only endpoint to set a meta flag on their account, and second, setting their display name to a script payload that bypasses escaping mechanisms.

Detection Guidance

Check for unauthorized script injections in user display names or avatar meta fields. Inspect WordPress user profiles for suspicious payloads in the display name field. Review logs for access to the nonce-only dismiss_ajax_call endpoint by non-admin users.

Impact Analysis

If exploited, this vulnerability could allow attackers to execute arbitrary web scripts in pages viewed by users. This could lead to theft of sensitive data, session hijacking, or defacement of your website. Users with subscriber-level access or higher could compromise the site's integrity and security.

Compliance Impact

This vulnerability could lead to data breaches, which may violate GDPR and HIPAA requirements for protecting user data. Non-compliance with these regulations can result in significant fines and legal consequences. The risk of unauthorized script execution increases the likelihood of such breaches.

Mitigation Strategies

Update the Wp Social Login and Register Social Counter plugin to the latest version. Remove or sanitize any injected scripts from user display names. Restrict subscriber-level access to sensitive endpoints and review user roles for unnecessary privileges.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97344. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart