PatchSiren cyber security CVE debrief
CVE-2026-65561 miniOrange CVE debrief
A Contributor Cross Site Scripting (XSS) vulnerability exists in WordPress Social Login and Register plugin versions up to 7.8.0. This issue allows a contributor to inject malicious scripts, potentially leading to unauthorized actions on affected WordPress installations. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of the plugin should apply updates to prevent XSS attacks. The CVE record was published on 2026-07-27T15:17:09.357Z and has not been modified since then. Additional review is needed to fully understand the impact and to confirm affected deployments.
- Vendor
- miniOrange
- Product
- WordPress Social Login and Register
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-07-27
Who should care
Users of WordPress Social Login and Register plugin versions up to 7.8.0 should apply updates to prevent XSS attacks. This includes administrators and security teams responsible for maintaining WordPress installations that utilize the affected plugin. Additionally, operators and platform managers should review the vulnerability to assess potential impact on their environments.
Technical summary
The CVE-2026-65561 vulnerability is a Contributor Cross Site Scripting (XSS) issue in the WordPress Social Login and Register plugin. It has a CVSS score of 6.5 and a severity of MEDIUM. The vulnerability allows a contributor to inject malicious scripts, potentially leading to unauthorized actions on affected WordPress installations. The issue was published on 2026-07-27T15:17:09.357Z and last modified on 2026-07-27T17:46:02.447Z. Further review is needed to fully understand the technical impact and to confirm affected deployments.
Defensive priority
Medium priority due to CVSS score and potential impact. Additional security measures should be considered to protect against potential XSS attacks.
Recommended defensive actions
- Apply updates to WordPress Social Login and Register plugin to version above 7.8.0.
- Monitor plugin updates and security advisories.
- Consider implementing additional security measures for WordPress installations.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
Evidence from Patchstack and NVD suggests a XSS vulnerability exists in the plugin. Further review is needed to fully understand the impact. The vulnerability allows a contributor to inject malicious scripts, potentially leading to unauthorized actions on the affected WordPress installations. Additional verification is required to assess the full scope of the vulnerability and to confirm affected deployments.
Official resources
-
CVE-2026-65561 CVE record
CVE.org
-
CVE-2026-65561 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T15:17:09.357Z and has not been modified since then.