CVE-2025-1506
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-1506 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Wp Social Login and Register Social Counter plugin for WordPress. Versions up to and including 3.1.0 are susceptible to this issue. The vulnerability stems from the lack of proper nonce validation on the counter_access_key_setup() function, which opens the door for unauthenticated attackers. By tricking a site administrator into performing a specific action, such as clicking on a malicious link, attackers can successfully update social login provider settings, potentially leading to serious security consequences.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.