PatchSiren

miniOrange CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM miniOrange CVE published 2026-07-27

CVE-2026-65561

A Contributor Cross Site Scripting (XSS) vulnerability exists in WordPress Social Login and Register plugin versions up to 7.8.0. This issue allows a contributor to inject malicious scripts, potentially leading to unauthorized actions on affected WordPress installations. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of the plugin should apply updates to prevent XSS attacks. The [truncated]