CVE-2026-82229: WordPress WordPress Social Login and Register plugin <= 7.8.2 - Cross Site Scripting (XSS) vulnerability
Published Aug 31, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
Affected Software
1 affected component
WordPress WordPress Social Login and Register<=7.8.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Social Login and Register pluginto a version that resolves this vulnerability.Fixed in 7.9.0
Event History
Aug 31, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation still requires user interaction, as reflected by the UI:R attack vector.
2
What impact could successful exploitation have?
Successful XSS can affect confidentiality, integrity, and availability at a low level, and its scope is changed beyond the vulnerable component. The reported CVSS score is 7.1 (High).
3
Which plugin versions are affected?
WordPress Social Login and Register versions 7.8.2 and earlier are identified as affected.