WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Loginizer Pro safe?

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

What this plugin does

  • Slug: loginizer-security
  • Author: Softaculous
  • 1000000+ active installs
  • 96/100 rating (1028 reviews on wordpress.org)
  • 30965148 all-time downloads
  • On WordPress.org since 2016-01-27

accessadminloginLoginizersecurity

Maintenance status

  • Last updated: 2026-05-08 1:34pm GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 5.5+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

1 known CVE on file for Loginizer Pro. Reported between 2024 and 2024.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10097 Loginizer [loginizer-security] < 1.9.3 Improper Authentication High 8.1 < 1.9.3 1.9.3 2024-11-04

CVE-2024-10097

The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

Source: CVE.org

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.