CVE-2026-97344 | roxnor Wp Social Login and Register Social Counter Plugin Avatar xs_social_get_avatar cross site scripting

SecurityVulns

A vulnerability described as problematic has been identified in roxnor Wp Social Login and Register Social Counter Plugin up to 3.2.1 on WordPress. Affected by this vulnerability is the function xs_social_get_avatar of the component Avatar Handler. The manipulation of the argument xs_social_profile_image/display name results in cross site scripting.

This vulnerability is reported as CVE-2026-97344. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More