PT-2026-73115 · WordPress · User-Login-History

·

CVE-2026-2283

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions User Login History versions prior to 2.1.8
Description The User Login History plugin for WordPress contains a SQL Injection flaw, which occurs when an application fails to properly sanitize or escape input used in a database query, allowing an attacker to interfere with the queries. This issue is caused by insufficient escaping of the user-supplied blog id parameter and a lack of proper preparation of the SQL query. Authenticated attackers with Administrator-level access or higher can append additional SQL queries to extract sensitive information from the database. This issue is only exploitable on multisite installations.
Recommendations Update User Login History to version 2.1.8 or later. As a temporary mitigation, restrict access to the blog id parameter in multisite environments until the update is applied.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2283

Affected Products

User-Login-History