CVE-2026-65561

WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.


We have discovered 201 live websites that are affected by CVE-2026-65561.

Run a Free Instant Scan




Affected Software

Product  Miniorange Login Openid
Category Wordpress Plugins
Vulnerable Domains201 live websites (100% of Miniorange Login Openid install base)
Vulnerable Versions
  • from 0 through 7.8
Vulnerable Versions Count10 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 27, 2026
  • Updated - Jul 27, 2026

Credits

  • Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-65561
United States74 websites



Singapore16 websites
Germany11 websites
Russia10 websites
Netherlands8 websites
Italy7 websites
Czech Republic7 websites
France6 websites
GB6 websites
Canada5 websites

Website Distribution by TLD

Number of websites using CVE-2026-65561
.com94 websites
.it8 websites
.nl8 websites
.org7 websites
.ru7 websites
.cz6 websites
.net5 websites
.ca4 websites
.co.uk4 websites
.eu3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65561

Top websites that are affected by CVE-2026-65561. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
**************.it United States***,***
****.****.edu United States***,***
*************.com United States***,***
****************.org United States***,***
******.se Sweden*,***,***
*************.com United States*,***,***
************.com United States*,***,***
*****.ua Ukraine*,***,***
*******.sg Singapore*,***,***
See full domain list

FAQ

CVE-2026-65561 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Miniorange Login Openid
A total of 201 websites have been identified as vulnerable to CVE-2026-65561, based on global website indexing conducted by WebTechSurvey.
The Miniorange Login Openid is affected by the CVE-2026-65561 vulnerability.
Miniorange Login Openid versions up to and including 7.8 are vulnerable to CVE-2026-65561.