Loginpress Pro
by WordPress
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-49058 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. | ||
| CVE-2025-7444 | Cri | 0.64 | 9.8 | 0.01 | Jul 18, 2025 | The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log… | ||
| CVE-2024-32676 | Med | 0.34 | 5.3 | 0.00 | Apr 25, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Important Client Functionality.This issue affects LoginPress Pro: from n/a before 3.0.0. | ||
| CVE-2024-32677 | Med | 0.34 | 5.3 | 0.01 | Apr 24, 2024 | Missing Authorization vulnerability in LoginPress LoginPress Pro.This issue affects LoginPress Pro: from n/a before 3.0.0. | ||
| CVE-2026-12598 | Hig | 0.00 | 8.1 | 0.01 | Jul 10, 2026 | The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me… | ||
| CVE-2026-12597 | Hig | 0.00 | 8.1 | 0.01 | Jul 10, 2026 | The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element… | ||
| CVE-2026-12595 | Hig | 0.00 | 8.1 | 0.01 | Jul 10, 2026 | The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field… |
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.
- risk 0.64cvss 9.8epss 0.01
The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log…
- risk 0.34cvss 5.3epss 0.00
Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Important Client Functionality.This issue affects LoginPress Pro: from n/a before 3.0.0.
- risk 0.34cvss 5.3epss 0.01
Missing Authorization vulnerability in LoginPress LoginPress Pro.This issue affects LoginPress Pro: from n/a before 3.0.0.
- risk 0.00cvss 8.1epss 0.01
The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me…
- risk 0.00cvss 8.1epss 0.01
The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element…
- risk 0.00cvss 8.1epss 0.01
The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field…