CVE-2026-73351: WordPress WordPress Social Login and Register plugin <= 7.8.1 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
Affected Software
1 affected component
WordPress WordPress Social Login and Register<=7.8.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Social Login and Registerto a version that resolves this vulnerability.Fixed in 7.8.2
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an account to exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or plugin-level credentials. Exploitation still requires user interaction, as reflected by the UI:R vector.
2
How can I determine whether my site may be affected?
Versions through 7.8.1 are affected according to the available data. Sites using the WordPress Social Login and Register plugin should determine whether their installed version is 7.8.1 or earlier.