WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Login & Register Forms – Popup, Slider, Profile & WooCommerce

Give your WordPress or WooCommerce website a modern login experience with beautiful, fast, and fully customizable forms.

10Reported vulnerabilities
8.8Highest CVSS score
4.0.2Latest version
40,000+Active installs

What to do now

Update Login & Register Forms – Popup, Slider, Profile & WooCommerce to 3.2.5 or later. 10 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 6, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2022-0215 High 8.8 0.8% 2.2 and earlier
2.0 and earlier
2.5.1 and earlier
2.5.2 January 18, 2022
CVE-2024-5324 High 8.8 1.5% 2.7.1 to 2.7.1 (inclusive)
2.7.2 to 2.7.2 (inclusive)
Before 2.6.2
2.5 to 2.5 (inclusive)
Before 2.6.1
2.6.2 June 6, 2024
CVE-2020-36715 Medium 4.6 0.7% 1.4 and earlier 1.5 June 7, 2023
CVE-2026-14836 High 8.1 0.2% Before 3.2.5 3.2.5 August 6, 2026
WF-3b8ea0b1-5050-43fc-8b80-b6a501a607fe Medium 6.1 2.1 and earlier 2.2 November 17, 2021
CVE-2025-1064 Medium 5.4 0.3% Before 2.8.6 2.8.6 February 20, 2025
CVE-2026-18470 Medium 5.3 0.3% 4.0.1 and earlier 4.0.2 August 5, 2026
CVE-2025-50027 Medium 4.4 0.2% 2.9.4 and earlier 2.9.5 June 19, 2025
CVE-2024-5665 Medium 4.3 0.4% 2.7.1 up to (but not including) 2.7.3 2.7.3 June 6, 2024
WF-3fa62b8f-1c2f-4bc9-9f2a-8b9765c2d30d Medium 4.3 Before 2.4 2.4 June 26, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.