WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in User Login History

Helps you to know your website's visitors by tracking their login related information like login/logout time, country, browser and many more.

5Reported vulnerabilities
8.8Highest CVSS score
2.1.8Latest version
10,000+Active installs

What to do now

Update User Login History to 2.1.8 or later. 5 of these have a fixed version available. Updating resolves them.

Plugin last updated: March 17, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
WF-2c25a344-4876-4ba8-bbc6-d1a32f4b1d08 High 8.8 1.7.0 to 1.7.0 (inclusive) 1.7.1 March 16, 2019
WF-6fb2d9ec-1082-4209-9fc9-6f10ba3a2398 High 8.8 1.7.0 to 1.7.0 (inclusive) 1.7.1 March 16, 2019
CVE-2017-15867 Medium 6.1 1.0% 1.5.2 and earlier 1.6 October 24, 2017
CVE-2025-47676 Medium 6.4 0.2% 2.1.6 and earlier 2.1.7 May 7, 2025
CVE-2026-2283 Medium 4.9 0.3% 0 to 2.1.7 (inclusive) 2.1.8 August 16, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.