PT-2026-84103 · WordPress · Persistent Login

·

CVE-2026-18752

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Persistent Login plugin for WordPress versions prior to 3.1.1
Description An issue exists where authenticated attackers with subscriber-level access and above can perform SQL Injection. This occurs due to insufficient escaping of the user-supplied parameter and lack of preparation on the existing SQL query. The flaw is triggered via the wppl device id Cookie and is only exploitable when the Login History feature is enabled. This allows attackers to append additional SQL queries to extract sensitive information from the database.
Recommendations Update the plugin to a version newer than 3.1.0. As a temporary mitigation, disable the Login History feature.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18752

Affected Products

Persistent Login