PLUGIN SECURITY

Is Login & Register Forms – Popup, Slider, Profile & WooCommerce safe?

Give your WordPress or WooCommerce website a modern login experience with beautiful, fast, and fully customizable forms.

What this plugin does

  • Slug: easy-login-woocommerce
  • Author: xootix
  • 40000+ active installs
  • 96/100 rating (254 reviews on wordpress.org)
  • 1247315 all-time downloads
  • On WordPress.org since 2018-04-04

2FAlogin popupotp loginsocial loginwoocommerce login

Maintenance status

  • Last updated: 2026-08-29 12:44pm GMT
  • Tested up to WordPress: 7.0.4
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

10 known CVEs on file for Login & Register Forms – Popup, Slider, Profile & WooCommerce.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-18469 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2 Improper Authentication Unknown < 4.0.2 4.0.2 2026-08-10
CVE-2026-18468 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2 Improper Authentication Unknown < 4.0.2 4.0.2 2026-08-10
CVE-2026-18470 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 4.0.2 4.0.2 2026-08-06
CVE-2026-14836 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 3.2.5 Improper Authentication Unknown < 3.2.5 3.2.5 2026-08-01
CVE-2025-50027 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.9.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 2.9.5 2.9.5 2025-06-19
CVE-2024-5324 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.7.3 Missing Authorization High 8.8 < 2.7.3 2.7.3 2024-06-05
CVE-2024-5665 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] >= 2.7.1 - <= 2.7.2 Missing Authorization Medium 4.3 2.7.1–2.7.3 2.7.3 2024-06-05
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.4 Unknown < 2.4 2.4 2023-06-26
+ 14 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.4 Unknown < 2.4 2.4 2023-06-26
CVE-2022-0215 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.3 Cross-Site Request Forgery (CSRF) High 8.8 < 2.3 2.3 2022-01-13
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.2 Unknown < 2.2 2.2 2021-11-17
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.2 Unknown < 2.2 2.2 2021-11-17
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 1.5 Unknown < 1.5 1.5 2020-05-14
CVE-2020-36715 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 1.5 Missing Authorization High 7.4 < 1.5 1.5 2020-05-14
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.8.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.8.6 2.8.6 0000-00-00
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.2 Unknown < 2.2 2.2
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 1.5 Unknown < 1.5 1.5
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.4 Unknown < 2.4 2.4
CVE-2020-36715 Login/Signup Popup < 1.5 - Authenticated Stored Cross-Site Scripting (XSS) Unknown < 1.5 1.5
Login/Signup Popup < 2.2 - Reflected Cross-Site Scripting Unknown < 2.2 2.2
Login/Signup Popup < 2.4 - Settings Reset via CSRF Unknown < 2.4 2.4
CVE-2025-1064 Login/Signup Popup ( Inline Form + Woocommerce ) < 2.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via xoo_el_action Shortcode Unknown < 2.8.6 2.8.6

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.