
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68998 is a Cross-Site Request Forgery (CSRF) vulnerability in the Heateor Social Login WordPress plugin (slug: heateor-social-login) that could allow unauthenticated attackers to force higher-privileged users to execute unwanted actions. The vulnerability affects all versions up to and including 1.1.39, with no official patch available at the time of disclosure. It was reported by researcher Trương Hữu Phúc (truonghuuphuc) on November 26, 2025, and published by Patchstack on December 26, 2025. The CVSS v3.1 base score is 5.4 (Medium) (Patchstack).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery) and stems from insufficient or absent CSRF token validation in one or more administrative actions within the Heateor Social Login plugin. An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress user (e.g., an administrator), silently submits a forged request to the plugin's endpoints on the victim's behalf. Exploitation requires user interaction — specifically, a privileged user must be tricked into visiting a crafted page or clicking a malicious link while authenticated to the target WordPress site (Patchstack).
Successful exploitation allows an unauthenticated attacker to perform unauthorized actions on behalf of a higher-privileged WordPress user, such as modifying plugin settings or altering social login configurations. The CVSS assessment indicates low integrity and low availability impact, with no direct confidentiality impact. While the individual impact is limited, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-68998. The EPSS score is extremely low at approximately 0.008%, reflecting a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies the priority as "Low," noting the security issue is unlikely to be exploited (Patchstack).
wp-admin/admin-ajax.php or plugin-specific action URLs) originating from unusual referrers or external domains.Referer headers pointing to external or unfamiliar domains, which may indicate a CSRF attempt was triggered from a third-party page.As of the disclosure date (December 26, 2025), no official patched version of the Heateor Social Login plugin has been released. Site administrators should monitor the WordPress plugin repository for an updated version and apply it immediately upon availability. As a temporary workaround, consider disabling the plugin until a patch is available, restricting access to WordPress admin areas via IP allowlisting, or deploying a Web Application Firewall (WAF) rule to block suspicious cross-origin POST requests to admin endpoints. Patchstack users with the vPatch feature enabled may receive virtual patching protection (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."