WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

8Reported vulnerabilities
9.8Highest CVSS score
2.0.9Latest version
1,000,000+Active installs

What to do now

Update Loginizer to 1.9.3 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 3, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2020-27615 Critical 9.8 52.3% Before 1.6.4 1.6.4 October 21, 2020
CVE-2018-11366 Medium 6.1 2.2% 1.3.8 to 1.3.8 (inclusive)
1.3.9 to 1.3.9 (inclusive)
1.4.0 May 22, 2018
CVE-2017-12650 Critical 9.8 1.8% 1.3.5 and earlier 1.3.6 August 7, 2017
CVE-2023-2296 Medium 6.1 0.5% Before 1.7.9 1.7.9 May 30, 2023
CVE-2017-12651 High 8.8 0.7% 1.3.5 and earlier 1.3.6 August 7, 2017
CVE-2024-10097 High 8.1 0.7% Before 1.9.3 1.9.3 November 5, 2024
CVE-2022-45084 Medium 6.1 0.4% 1.7.5 and earlier 1.7.6 May 12, 2022
CVE-2022-45079 Medium 4.3 0.3% Before 1.7.6 1.7.6 December 5, 2022

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.