PLUGIN SECURITY
Is Loginpress safe?
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
What this plugin does
- Slug:
loginpress - Author: Adnan
- 200000+ active installs
- 96/100 rating (1075 reviews on wordpress.org)
- 7988337 all-time downloads
- On WordPress.org since 2016-09-08
custom loginloginlogin customizerwordpress loginwp login
Maintenance status
- Latest known version: 6.2.5
- Last updated: 2026-07-10 10:21am GMT
- Tested up to WordPress: 7.0.4
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
5 known CVEs on file for Loginpress.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2022-41839 | LoginPress | wp-login Custom Login Page Customizer [loginpress] < 1.6.3 | — | Medium 5.3 | < 1.6.3 | 1.6.3 | 2022-11-07 | ✓ fixed in latest |
| CVE-2022-0347 | LoginPress | wp-login Custom Login Page Customizer [loginpress] < 1.5.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.5.12 | 1.5.12 | 2022-02-14 | ✓ fixed in latest |
| CVE-2019-15871 | LoginPress | wp-login Custom Login Page Customizer [loginpress] < 1.1.4 | Missing Authorization | Medium 4.3 | < 1.1.4 | 1.1.4 | 2019-07-11 | ✓ fixed in latest |
| CVE-2019-15872, CVE-2019-15871 | LoginPress | wp-login Custom Login Page Customizer [loginpress] < 1.1.16 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 1.1.16 | 1.1.16 | 2018-12-07 | ✓ fixed in latest |
| — | LoginPress | wp-login Custom Login Page Customizer [loginpress] < 1.1.16 | — | Unknown | < 1.1.16 | 1.1.16 | 2018-12-07 | ✓ fixed in latest |
| — | LoginPress | wp-login Custom Login Page Customizer [loginpress] < 4.0.0 | Cross-Site Request Forgery (CSRF) | High 7.5 | < 4.0.0 | 4.0.0 | 0000-00-00 | ✓ fixed in latest |
| — | LoginPress | wp-login Custom Login Page Customizer [loginpress] < 1.1.16 | — | Unknown | < 1.1.16 | 1.1.16 | — | ✓ fixed in latest |
| — | LoginPress <= 1.1.15 - Authenticated Blind SQL Injection | — | Unknown | < 1.1.16 | 1.1.16 | — | ✓ fixed in latest |
+ 1 more known vulnerability
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-1764 | LoginPress < 4.0.0 - Arbitrary Options Update via CSRF | — | Unknown | < 4.0.0 | 4.0.0 | — | ✓ fixed in latest |
How to fix it
Keep Loginpress updated — 6.2.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WPS Hide Login — 2000000+ active installs — 96/100 (2111) — max PHP 8.4
- Loginizer — 1000000+ active installs — 96/100 (1030) — max PHP <8.0
- Security Optimizer – The All-In-One Protection Plugin — 1000000+ active installs — 90/100 (157) — max PHP <8.0
- Limit Login Attempts — 300000+ active installs — 92/100 (202) — max PHP 8.4
- WPS Limit Login — 100000+ active installs — 98/100 (83)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.