Skip to main content

Software intelligence

Woo Social Login vulnerabilities

10 tracked advisories · slug woo-social-login

Important: Woo Social Login appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works

Tracked advisories

10

Latest advisory

1 August 2026

CISA KEV matches

0

In this WordPress feed

WordPress slug

woo-social-login

Plugin

What this means for Woo Social Login

This catalog lists 10 known advisories affecting Woo Social Login. The most recent was published on 1 August 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.

Latest issues

  • WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT

    May allow access to accounts or admin areas without valid credentials.

    Published 1 August 2026

  • WooCommerce Social Login <= 2.8.2 - Cross-Site Request Forgery

    May trick authenticated users into performing unintended actions.

    Published 16 April 2025

  • Social Login - WordPress / WooCommerce Plugin <= 2.7.7 - Authentication Bypass via WordPress.com OAuth provider

    May allow access to accounts or admin areas without valid credentials.

    Published 4 November 2024

Vulnerability types

  • Authentication bypass4
  • Privilege escalation2
  • CSRF1

Authentication (inferred from titles)

  • Unauthenticated6
  • Authenticated0
  • Unspecified4

Advisory history

Known Woo Social Login advisories published by month.

All advisories

Check whether your installed version is affected

SiteRespond Defence matches your installed Woo Social Login version against this catalog when the Defence plugin is connected to your WordPress site.