WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Login Widget With Shortcode

This is a simple login form in the widget. This will allow users to login to the site from frontend.

2Reported vulnerabilities
6.1Highest CVSS score
6.1.3Latest version
6,000+Active installs

What to do now

Update Login Widget With Shortcode to 3.2.1 or later. 1 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 11, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2014-6312 Medium 4.3 4.2% 3.1.1 and earlier
1.0.1 to 1.0.1 (inclusive)
2.0.1 to 2.0.1 (inclusive)
2.0.2 to 2.0.2 (inclusive)
2.1.3 to 2.1.3 (inclusive)
2.2.3 to 2.2.3 (inclusive)
2.2.4 to 2.2.4 (inclusive)
3.2.1 October 15, 2014
CVE-2024-54255 Medium 6.1 0.4% 6.1.2 and earlier December 5, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.