Resources /
WordPress Plugins /
Loginizer Pro
PLUGIN SECURITY
Is Loginizer Pro safe?
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
What this plugin does
- Slug:
loginizer-security
- Author: Softaculous
- 1000000+ active installs
- 96/100 rating (1028 reviews on wordpress.org)
- 30965148 all-time downloads
- On WordPress.org since 2016-01-27
accessadminloginLoginizersecurity
Maintenance status
- Last updated: 2026-05-08 1:34pm GMT
- Tested up to WordPress: 7.0.2
- Requires PHP: 5.5+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
1 known CVE on file for Loginizer Pro.
Reported between 2024 and 2024.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-10097
|
Loginizer [loginizer-security] < 1.9.3 |
Improper Authentication |
High
8.1
|
< 1.9.3
|
1.9.3 |
2024-11-04 |
—
|
CVE-2024-10097
The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.
Source:
CVE.org
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.