VYPR

Loginpress Pro

by WordPress

CVEs (7)

  • CVE-2026-49058CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.

  • CVE-2025-7444CriJul 18, 2025
    risk 0.64cvss 9.8epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log…

  • CVE-2024-32676MedApr 25, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Important Client Functionality.This issue affects LoginPress Pro: from n/a before 3.0.0.

  • CVE-2024-32677MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in LoginPress LoginPress Pro.This issue affects LoginPress Pro: from n/a before 3.0.0.

  • CVE-2026-12598HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me…

  • CVE-2026-12597HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element…

  • CVE-2026-12595HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field…