WP Social AutoConnect

WP Social AutoConnect has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2025; 4 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.1 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 3 of the records (60%). Other recurring categories include Cross-Site Scripting.

4 of the records (80%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

4 independent researchers contributed these findings, one record each. WP Social AutoConnect is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.3.10.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage80%
Open

1

Fixed

4

Get automatic notifications for all WP Social AutoConnect vulnerabilities before they are exploited.

Most severe open issueCVSS 4.4CVE-2025-50022

WP-FB-AutoConnect <= 4.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

5 records
Plugin Profile
Latestv4.6.4

WP Social AutoConnect

JK

Author

JK

4.4(13)
88/100
Last Updated
2025-08-13 (1y ago)
Active Installs
400+
Downloads
385,747
Requires WP
2.5+
Requires PHP
0+
Tested up to
WP 6.3.10
Created
2010-03-16 (17y ago)

The simple concept behind WP-FB AutoConnect is to offer an easy-to-use widget that lets readers login to your blog with either their Facebook account or local WordPress credentials. Although many “Facebook Connect” plugins do exist, most of them are either overly complex and difficult to customize, or fail to provide a seamless experience for new visitors. I wrote this plugin to provide what the others didn’t: Full support for both WordPress and Buddypress. No user interaction is required – the login process is transparent to new and returning users alike. Existing users who connect with FB retain the same local user accounts as before (matched via e-mail). New visitors will be given new user accounts, which can be retained even if you remove the plugin. Facebook profile pictures can be used as avatars. No contact with the Facebook API after the login completes – so no slow pageloads. No 3rd party services: your site talks directly to Facebook, through an app created and owned by you. Won’t bloat your database with duplicate user accounts, extra fields, or unnecessary complications. Custom logging options can notify you whenever someone connects with Facebook. A powerful set of hooks and filters allow developers to easily tailor the login process to their personal needs: redirect to a custom page, fill xProfile data with information from Facebook, setup permissions based on social connections, and more. Fully HTML/CSS valid. Donate Countless hours have gone into developing, maintaining, & supporting this plugin. Just keeping it running requires ongoing work due to Facebook’s ever-changing API & WordPress’ frequent updates. If you find it useful, please consider supporting its continued development by making a donation of any amount. Privacy This plugin uses the Facebook API to fetch data from Facebook. The data is used to automate user logins, and/or to automate the creation of new local WordPress user accounts. The data may therefore be copied & stored in the WordPress database, and can be removed by deleting any Facebook-linked user accounts. Usage of this plugin means the site administrator is consenting to Facebook’s data policy. Note that using the Facebook API requires loading some JS from Facebook, which may track visitors. This plugin does not use any 3rd party intermediary for processing logins or otherwise – all data is exchanged directly between your site & Facebook. Support Please direct all support requests here

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C