Social Share, Social Login and Social Comments Plugin – Super Socializer

Social Share, Social Login and Social Comments Plugin – Super Socializer has 14 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2026; 11 are fixed and 3 remain unpatched as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 2 high. 2023 was the busiest year with 5 disclosures.

The most common weakness is Cross-Site Scripting, behind 8 of the records (57%). Other recurring categories include Missing Authorization, Authentication Bypass Using An Alternate Path Or Channel.

11 of the records (79%) have a vendor fix, while 3 remain unpatched. The oldest unresolved one dates back to 2026.

10 independent researchers contributed these findings, most of them (3) reported by Rafshanzani Suhada.

01234567891003.03.2018Today03.03.20189.8Social Share, Social Login and Social Comments <= 7.10.6 - Authentication Bypass CVSS 9.8 · 03.03.201815.03.20226.1Social Share, Social Login and Social Comments < 7.13.30 - Reflected Cross-Site Scripting CVSS 6.1 · 15.03.202223.12.20226.4Super Socializer <= 7.13.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 23.12.202229.05.20236.1Social Share, Social Login and Social Comments <= 7.13.51 - Reflected Cross-Site Scripting CVSS 6.1 · 29.05.202319.06.20236.4Super Socializer <= 7.13.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 19.06.202311.07.20236.4Super Socializer <= 7.13.53 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 11.07.202305.09.20234.3Super Socializer <= 7.13.54 - Missing Authorization CVSS 4.3 · 05.09.20234.3Super Socializer <= 7.13.54 - Cross-Site Request Forgery CVSS 4.3 · 05.09.202325.03.20244.4Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.63 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 25.03.202405.11.20248.1Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.68 - Authentication Bypass via Disqus OAuth provider CVSS 8.1 · 05.11.202420.01.20255.3Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.14 - Unauthenticated Limited SQL Injection via 'SuperSocializerKey' CVSS 5.3 · 20.01.202507.07.20266.1Social Share, Social Login and Social Comments Plugin <= 7.14.5 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter CVSS 6.1 · 07.07.202628.07.20267.2Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.14.5 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 28.07.20265.3Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.14.5 - Missing Authorization CVSS 5.3 · 28.07.2026

Strategic Overview

Avg CVSSMedium
6.2/ 10
Patch Coverage79%
Open

3

Fixed

11

Get automatic notifications for all Social Share, Social Login and Social Comments Plugin – Super Socializer vulnerabilities before they are exploited.

Most severe open issueCVSS 7.2CVE-2026-65544

Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.14.5 - Unauthenticated Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

14 records
2026-07-28 00:00CVE-2026-65544
7.2
High
lqcNo
2026-07-28 00:00CVE-2026-65542
5.3
Medium
Nguyen Dinh Hai (HaiND)No
2026-07-07 17:03CVE-2026-11798
6.1
Medium
Nguyen Thanh Nguyen (tsug0d)No
2025-01-20 22:38CVE-2024-13230
5.3
Medium
mikemyersYes
2024-11-05 00:00CVE-2024-9946
8.1
High
wesley (wcraft)Yes
2024-03-25 00:00CVE-2024-2836
4.4
Medium
Dmitrii IgnatyevYes
2023-09-05 00:00CVE-2023-41802
4.3
Medium
Rafshanzani SuhadaYes
2023-09-05 00:00CVE-2023-41802
4.3
Medium
Rafshanzani SuhadaYes
2023-07-11 00:00N/A
6.4
Medium
AnonymousYes
2023-06-19 00:00CVE-2023-35882
6.4
Medium
Rafshanzani SuhadaYes
Showing 1–10 of 14 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C