PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65561 miniOrange CVE debrief

A Contributor Cross Site Scripting (XSS) vulnerability exists in WordPress Social Login and Register plugin versions up to 7.8.0. This issue allows a contributor to inject malicious scripts, potentially leading to unauthorized actions on affected WordPress installations. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of the plugin should apply updates to prevent XSS attacks. The CVE record was published on 2026-07-27T15:17:09.357Z and has not been modified since then. Additional review is needed to fully understand the impact and to confirm affected deployments.

Vendor
miniOrange
Product
WordPress Social Login and Register
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Users of WordPress Social Login and Register plugin versions up to 7.8.0 should apply updates to prevent XSS attacks. This includes administrators and security teams responsible for maintaining WordPress installations that utilize the affected plugin. Additionally, operators and platform managers should review the vulnerability to assess potential impact on their environments.

Technical summary

The CVE-2026-65561 vulnerability is a Contributor Cross Site Scripting (XSS) issue in the WordPress Social Login and Register plugin. It has a CVSS score of 6.5 and a severity of MEDIUM. The vulnerability allows a contributor to inject malicious scripts, potentially leading to unauthorized actions on affected WordPress installations. The issue was published on 2026-07-27T15:17:09.357Z and last modified on 2026-07-27T17:46:02.447Z. Further review is needed to fully understand the technical impact and to confirm affected deployments.

Defensive priority

Medium priority due to CVSS score and potential impact. Additional security measures should be considered to protect against potential XSS attacks.

Recommended defensive actions

  • Apply updates to WordPress Social Login and Register plugin to version above 7.8.0.
  • Monitor plugin updates and security advisories.
  • Consider implementing additional security measures for WordPress installations.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence from Patchstack and NVD suggests a XSS vulnerability exists in the plugin. Further review is needed to fully understand the impact. The vulnerability allows a contributor to inject malicious scripts, potentially leading to unauthorized actions on the affected WordPress installations. Additional verification is required to assess the full scope of the vulnerability and to confirm affected deployments.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T15:17:09.357Z and has not been modified since then.