CVE-2026-73351

WordPress WordPress Social Login and Register plugin <= 7.8.1 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.


We have discovered 201 live websites that are affected by CVE-2026-73351.

Run a Free Instant Scan




Affected Software

Product  Miniorange Login Openid
Category Wordpress Plugins
Vulnerable Domains201 live websites (100% of Miniorange Login Openid install base)
Vulnerable Versions
  • from 0 through 7.8.1
Vulnerable Versions Count14 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Credits

  • hackthesoul | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-73351
United States76 websites



Singapore18 websites
Germany11 websites
Russia10 websites
Netherlands8 websites
Italy8 websites
GB6 websites
France5 websites
Canada5 websites
Czech Republic5 websites

Website Distribution by TLD

Number of websites using CVE-2026-73351
.com91 websites
.it9 websites
.nl8 websites
.org7 websites
.ru7 websites
.net5 websites
.ca4 websites
.co.uk4 websites
.cz4 websites
.com.br3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73351

Top websites that are affected by CVE-2026-73351. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
**************.it United States***,***
****.****.edu United States***,***
*************.com United States***,***
****************.org United States***,***
******.se Sweden*,***,***
*************.com United States*,***,***
************.com United States*,***,***
*****.ua Ukraine*,***,***
*******.sg Singapore*,***,***
See full domain list

FAQ

CVE-2026-73351 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Miniorange Login Openid
A total of 201 websites have been identified as vulnerable to CVE-2026-73351, based on global website indexing conducted by WebTechSurvey.
The Miniorange Login Openid is affected by the CVE-2026-73351 vulnerability.
Miniorange Login Openid versions up to and including 7.8.1 are vulnerable to CVE-2026-73351.