Loginizer is a WordPress authentication and security plugin whose vulnerability profile concentrates on a single, widely deployed product protecting user login endpoints. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and frequent public exploit availability, while the recurring weakness classes—cross-site scripting, cross-site request forgery, SQL injection, and improper authentication—reflect the authentication and input-handling demands of a plugin managing credential flows and administrative access. Defenders should treat Loginizer advisories as actionable for WordPress deployments relying on this plugin; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Loginizer over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27615CRITICAL The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip. | Oct 21, 2020 | 9.8 | 78 | NO | YES |
CVE-2017-12650CRITICAL SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header. | Aug 7, 2017 | 9.8 | 28 | NO | NO |
CVE-2022-45079HIGH Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions. | May 22, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-10097HIGH The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verifica | Nov 5, 2024 | 8.1 | 25 | NO | NO |
CVE-2017-12651HIGH Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is | Aug 7, 2017 | 8.8 | 25 | NO | NO |
CVE-2022-45084MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions. | Apr 24, 2023 | 6.1 | 22 | NO | NO |
CVE-2018-11366MEDIUM init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0. | May 22, 2018 | 6.1 | 21 | NO | NO |
CVE-2023-2296MEDIUM The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used again | May 30, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Loginizer.
Media articles that mention a CVE ID that affects a product developed by Loginizer — matched by CVE ID, not by vendor name.