← WordPress Vulnerabilities
WordPress security by component

Persistent Login

Persistent Login (wp-persistent-login) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 01, 2026; the highest published CVSS base score is 8.5.

Plugin slug: wp-persistent-login

CVE-2026-18752: Persistent Login permits Subscriber-level SQL injection

Persistent Login through 3.1.0 uses the attacker-controlled wppl_device_id cookie in an insufficiently prepared SQL query. When Login History is enabled, a Subscriber or higher can append SQL and extract sensitive information from the WordPress database.

PublishedSep 01, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for wp-persistent-login
Safe version
Sep 01, 2026 CVE-2026-18752
Persistent Login permits Subscriber-level SQL injection
Persistent Login through 3.1.0 uses the attacker-controlled wppl_device_id cookie in an insufficiently prepared SQL query. When Login History is enabled, a Subscriber or higher can append SQL and extract sensitive information from the WordPress database.
See mitigation notes
CVE6.5
NVDPending
Aug 20, 2026 CVE-2026-66594
WordPress Persistent Login permits Subscriber-level SQL injection
WordPress Persistent Login <= 3.1.0 allows a Subscriber to place crafted input into an SQL query without adequate neutralization. The CVSS vector assigns high confidentiality and low availability impact, indicating database disclosure and query disruption without a separately claimed write primitive.
3.1.1
CVE8.5
NVDPending