The plugin does not have Cross-Site Request Forgery (CSRF) check when updating user social login option, which could allow attackers to make logged in users do such action on their behalf via a Cross-Site Request Forgery (CSRF) attack.