Input validation vulnerability in miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon 7.7.0

The plugin called “Social Login and Register” for WordPress is not safe to use if you have version 7.7.0 or lower. This means that hackers with administrator-level access or higher can access and run any files they want on the server. This can lead to them gaining unauthorized access to information, or even controlling the website by running their own code. This can happen even if the files being uploaded seem harmless, like images.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.