CVE-2024-32674: Heateor Social Login

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

Affected products

  • Heateor Social Login: before 1.1.32 (fixed in 1.1.32)

Published 2024-05-08. Last modified 2026-06-17.