miled / wordpress-social-login

WordPress Social Login
http://miled.github.io/wordpress-social-login/
MIT License
398 stars 237 forks source link

3 vulnerabilities in Wordpress Social Login #389

Open xberg opened 6 months ago

xberg commented 6 months ago

Hello, 3 vulnerabilities in WSL were publicly disclosed in September 2023. I would be very happy if you could have a look at these and offer a fix: https://patchstack.com/database/vulnerability/wordpress-social-login/wordpress-wordpress-social-login-plugin-3-0-4-cross-site-scripting-xss-vulnerability?_a_id=110 https://patchstack.com/database/vulnerability/wordpress-social-login/wordpress-wordpress-social-login-plugin-3-0-4-cross-site-scripting-xss-vulnerability-2?_a_id=110 https://patchstack.com/database/vulnerability/wordpress-social-login/wordpress-wordpress-social-login-plugin-3-0-4-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability?_a_id=110

Also I see you offer here version 3.0.5: the last version available in my Wordpress admin dashboard is 3.0.4.