← WordPress Vulnerabilities
WordPress security by component

LoginPress Pro

LoginPress Pro is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jul 10, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: loginpress-pro

CVE-2026-12598: LoginPress Pro: Privilege escalation or authentication bypass

LoginPress Pro is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 6.2.3.

PublishedJul 10, 2026
Known safe version> 6.2.3
Safe version
Jul 10, 2026 CVE-2026-12598
LoginPress Pro: Privilege escalation or authentication bypass
LoginPress Pro is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 6.2.3.
> 6.2.3
CVE8.1
NVDPending
Jul 10, 2026 CVE-2026-12597
LoginPress Pro: Privilege escalation or authentication bypass
LoginPress Pro is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 6.2.3.
> 6.2.3
CVE8.1
NVDPending
Jul 10, 2026 CVE-2026-12595
LoginPress Pro: Privilege escalation or authentication bypass
LoginPress Pro is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 6.2.3.
> 6.2.3
CVE8.1
NVDPending
Jun 17, 2026 CVE-2026-49058
LoginPress Pro: Privilege escalation or authentication bypass
LoginPress Pro is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 6.2.2.
6.2.3
CVE9.8
NVDPending
Jul 18, 2025 CVE-2025-7444
LoginPress Pro: Privilege escalation or authentication bypass
LoginPress Pro is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Apr 25, 2024 CVE-2024-32676
LoginPress Pro: A security weakness
LoginPress Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 24, 2024 CVE-2024-32677
LoginPress Pro: A security weakness
LoginPress Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending