VYPR

Theme My Login

by WordPress

Source repositories

CVEs (6)

  • CVE-2023-6272CriDec 18, 2023
    risk 0.64cvss 9.8epss 0.01

    The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

  • CVE-2025-60098MedSep 26, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Jeff Farthing Theme My Login theme-my-login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theme My Login: from n/a through <= 7.1.12.

  • CVE-2026-66681MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.

  • CVE-2024-32525MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Theme My Login.This issue affects Theme My Login: from n/a through 7.1.6.

  • CVE-2026-83628MedSep 5, 2026
    risk 0.21cvss 4.3epss 0.00

    The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherblog` branch failing to enforce the network's `active_signup`…

  • CVE-2024-7422MedAug 16, 2024
    risk 0.21cvss 4.3epss 0.00

    The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.1.7. This is due to missing or incorrect nonce validation on the tml_admin_save_ms_settings() function. This makes it possible for unauthenticated…