Persistent Login
by WordPress
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66594 | Hig | 0.55 | 8.5 | 0.00 | Aug 20, 2026 | Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | ||
| CVE-2026-94081 | Hig | 0.46 | 7.1 | — | Sep 30, 2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. | ||
| CVE-2026-18752 | Med | 0.42 | 6.5 | 0.00 | Sep 1, 2026 | The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… |
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
- risk 0.46cvss 7.1epss —
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
- risk 0.42cvss 6.5epss 0.00
The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…