PLUGIN SECURITY
Is Login & Register Forms – Popup, Slider, Profile & WooCommerce safe?
Give your WordPress or WooCommerce website a modern login experience with beautiful, fast, and fully customizable forms.
What this plugin does
- Slug:
easy-login-woocommerce - Author: xootix
- 40000+ active installs
- 96/100 rating (254 reviews on wordpress.org)
- 1247315 all-time downloads
- On WordPress.org since 2018-04-04
2FAlogin popupotp loginsocial loginwoocommerce login
Maintenance status
- Last updated: 2026-08-29 12:44pm GMT
- Tested up to WordPress: 7.0.4
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
10 known CVEs on file for Login & Register Forms – Popup, Slider, Profile & WooCommerce.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-18469 | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2 | Improper Authentication | Unknown | < 4.0.2 | 4.0.2 | 2026-08-10 | — |
| CVE-2026-18468 | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2 | Improper Authentication | Unknown | < 4.0.2 | 4.0.2 | 2026-08-10 | — |
| CVE-2026-18470 | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2 | Exposure of Sensitive Information to an Unauthorized Actor | Unknown | < 4.0.2 | 4.0.2 | 2026-08-06 | — |
| CVE-2026-14836 | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 3.2.5 | Improper Authentication | Unknown | < 3.2.5 | 3.2.5 | 2026-08-01 | — |
| CVE-2025-50027 | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.9.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 2.9.5 | 2.9.5 | 2025-06-19 | — |
| CVE-2024-5324 | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.7.3 | Missing Authorization | High 8.8 | < 2.7.3 | 2.7.3 | 2024-06-05 | — |
| CVE-2024-5665 | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] >= 2.7.1 - <= 2.7.2 | Missing Authorization | Medium 4.3 | 2.7.1–2.7.3 | 2.7.3 | 2024-06-05 | — |
| — | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.4 | — | Unknown | < 2.4 | 2.4 | 2023-06-26 | — |
+ 14 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.4 | — | Unknown | < 2.4 | 2.4 | 2023-06-26 | — |
| CVE-2022-0215 | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.3 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 2.3 | 2.3 | 2022-01-13 | — |
| — | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.2 | — | Unknown | < 2.2 | 2.2 | 2021-11-17 | — |
| — | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.2 | — | Unknown | < 2.2 | 2.2 | 2021-11-17 | — |
| — | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 1.5 | — | Unknown | < 1.5 | 1.5 | 2020-05-14 | — |
| CVE-2020-36715 | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 1.5 | Missing Authorization | High 7.4 | < 1.5 | 1.5 | 2020-05-14 | — |
| — | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.8.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.8.6 | 2.8.6 | 0000-00-00 | — |
| — | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.2 | — | Unknown | < 2.2 | 2.2 | — | — |
| — | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 1.5 | — | Unknown | < 1.5 | 1.5 | — | — |
| — | Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.4 | — | Unknown | < 2.4 | 2.4 | — | — |
| CVE-2020-36715 | Login/Signup Popup < 1.5 - Authenticated Stored Cross-Site Scripting (XSS) | — | Unknown | < 1.5 | 1.5 | — | — |
| — | Login/Signup Popup < 2.2 - Reflected Cross-Site Scripting | — | Unknown | < 2.2 | 2.2 | — | — |
| — | Login/Signup Popup < 2.4 - Settings Reset via CSRF | — | Unknown | < 2.4 | 2.4 | — | — |
| CVE-2025-1064 | Login/Signup Popup ( Inline Form + Woocommerce ) < 2.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via xoo_el_action Shortcode | — | Unknown | < 2.8.6 | 2.8.6 | — | — |
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Wordfence Security – Firewall, Malware Scan, and Login Security — 5000000+ active installs — 94/100 (4986) — max PHP 8.4
- Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) — 3000000+ active installs — 98/100 (8863) — max PHP 8.4
- Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention — 1000000+ active installs — 96/100 (1478) — max PHP 8.4
- Two Factor — 100000+ active installs — 96/100 (208) — max PHP 8.4
- WP 2FA – Two-factor authentication for WordPress — 100000+ active installs — 94/100 (177)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.