The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback set to __return_true and lacking capability or nonce validation in their handlers. This makes it possible for unauthenticated attackers to clear or overwrite the social counter cache via crafted REST requests.
History

Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Roxnor
Roxnor wp Social Login And Register Social Counter
Wordpress
Wordpress wordpress
Vendors & Products Roxnor
Roxnor wp Social Login And Register Social Counter
Wordpress
Wordpress wordpress

Fri, 05 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 11:15:00 +0000

Type Values Removed Values Added
Description The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback set to __return_true and lacking capability or nonce validation in their handlers. This makes it possible for unauthenticated attackers to clear or overwrite the social counter cache via crafted REST requests.
Title Wp Social Login and Register Social Counter <= 3.1.3 - Missing Authorization in Cache REST Endpoints to Social Counter Tampering
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-12-05T12:21:58.651Z

Reserved: 2025-11-24T20:43:17.834Z

Link: CVE-2025-13620

cve-icon Vulnrichment

Updated: 2025-12-05T12:21:54.929Z

cve-icon NVD

Status : Received

Published: 2025-12-05T11:15:51.530

Modified: 2025-12-05T11:15:51.530

Link: CVE-2025-13620

cve-icon Redhat

No data.