WordPress security by component
Persistent Login
Persistent Login (wp-persistent-login) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 01, 2026; the highest published CVSS base score is 8.5.
Plugin slug:
wp-persistent-loginLatest vulnerability
CVE-2026-18752: Persistent Login permits Subscriber-level SQL injection
Persistent Login through 3.1.0 uses the attacker-controlled wppl_device_id cookie in an insufficiently prepared SQL query. When Login History is enabled, a Subscriber or higher can append SQL and extract sensitive information from the WordPress database.
| Safe version |
|
||
|---|---|---|---|
| Sep 01, 2026 |
CVE-2026-18752
Persistent Login permits Subscriber-level SQL injection
Persistent Login through 3.1.0 uses the attacker-controlled wppl_device_id cookie in an insufficiently prepared SQL query. When Login History is enabled, a Subscriber or higher can append SQL and extract sensitive information from the WordPress database.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 20, 2026 |
CVE-2026-66594
WordPress Persistent Login permits Subscriber-level SQL injection
WordPress Persistent Login <= 3.1.0 allows a Subscriber to place crafted input into an SQL query without adequate neutralization. The CVSS vector assigns high confidentiality and low availability impact, indicating database disclosure and query disruption without a separately claimed write primitive.
|
3.1.1 |
CVE8.5
NVDPending
|