PT-2026-84103 · WordPress · Persistent Login
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Persistent Login plugin for WordPress versions prior to 3.1.1
Description
An issue exists where authenticated attackers with subscriber-level access and above can perform SQL Injection. This occurs due to insufficient escaping of the user-supplied parameter and lack of preparation on the existing SQL query. The flaw is triggered via the
wppl device id Cookie and is only exploitable when the Login History feature is enabled. This allows attackers to append additional SQL queries to extract sensitive information from the database.Recommendations
Update the plugin to a version newer than 3.1.0.
As a temporary mitigation, disable the Login History feature.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Persistent Login