plugin

Easy Login Woocommerce Vulnerabilities

25 known security issues reported for the Easy Login Woocommerce WordPress plugin. Most recent disclosed Aug 6, 2026.

4 high 6 medium

Running Easy Login Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Login & Register Forms – Popup, Slider, Profile & WooCommerce < 3.2.5 - Authentication Bypass via Brute Force

high

The Login & Register Forms – Popup, Slider, Profile & WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to 3.2.5 (exclusive). This makes it possible for unauthenticated attackers to brute force a password reset verification key that may make it possible to take over accounts.

CVSS:
8.1
Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Aug 6, 2026

CVE-2026-14836 on NVD →

Login & Register Forms <= 4.0.1 - Unauthenticated Registered User Email Address Disclosure

medium

The Login & Register Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.0.1. This is due to the lost-password code-flow response including the target account's email address (masked or unmasked) rather than returning a generic acknowledgement message. This mak...

CVSS:
5.3
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
Aug 5, 2026

CVE-2026-18470 on NVD →

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 2.9.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xootix Login/Signup Popup allows Stored XSS. This issue affects Login/Signup Popup: from n/a through 2.9.4.

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jun 20, 2025

CVE-2025-50027 on NVD →

Login/Signup Popup <= 2.9.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Login/Signup Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in p...

CVSS:
4.4
Affected:
up to 2.9.4
Fixed in:
2.9.5
Disclosed:
Jun 19, 2025

CVE-2025-50027 on NVD →

Login/Signup Popup ( Inline Form + Woocommerce ) <= 2.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via xoo_el_action Shortcode

medium

The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's xoo_el_action shortcode in all versions up to, and including, 2.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a...

CVSS:
6.4
Affected:
up to 2.8.5
Fixed in:
2.8.6
Disclosed:
Feb 19, 2025

CVE-2025-1064 on NVD →

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] >= 2.7.1 - <= 2.7.2

unknown

[en] The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ‘export_settings’ function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read...

Affected:
2.7.1 – 2.7.2
Fixed in:
2.7.2
Disclosed:
Jun 6, 2024

CVE-2024-5665 on NVD →

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 2.7.3

unknown

[en] The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...

Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Jun 6, 2024

CVE-2024-5324 on NVD →

Login/Signup Popup ( Inline Form + Woocommerce ) 2.7.1 - 2.7.2 - Missing Authorization to Arbitrary Options Exposure

medium

The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ‘export_settings’ function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbit...

CVSS:
4.3
Affected:
2.7.1 – 2.7.2
Fixed in:
2.7.3
Disclosed:
Jun 5, 2024

CVE-2024-5665 on NVD →

XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update

high

Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary optio...

CVSS:
8.8
Affected:
2.7.1 – 2.7.2
Fixed in:
2.7.3
Disclosed:
Jun 5, 2024

CVE-2024-5324 on NVD →

Login/Signup Popup <= 2.3 - Cross-Site Request Forgery to Settings Reset

medium

The Login/Signup Popup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3. This is due to missing nonce validation on the reset_settings() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they c...

CVSS:
4.3
Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Jun 26, 2023

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 2.4

unknown

The Login/Signup Popup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3. This is due to missing nonce validation on the reset_settings() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they c...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Jun 26, 2023

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 2.4

unknown

Update the WordPress Login/Signup Popup plugin to the latest available version (at least 2.4). An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Login/Signup Popup Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted ac...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Jun 26, 2023

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 1.5

unknown

[en] The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can success...

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Jun 7, 2023

CVE-2020-36715 on NVD →

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 2.3

unknown

[en] The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for...

Affected:
up to 2.3
Fixed in:
2.3
Disclosed:
Jan 18, 2022

CVE-2022-0215 on NVD →

Login/Signup Popup <= 2.2 - Cross-Site Request Forgery to Arbitrary Options Update

high

The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for atta...

CVSS:
8.8
Affected:
up to 2.2
Fixed in:
2.3
Disclosed:
Jan 13, 2022

CVE-2022-0215 on NVD →

Login/Signup Popup ( Inline Form + Woocommerce ) <= 2.1 - Reflected Cross-Site Scripting

medium

The plugin Login/Signup Popup ( Inline Form + Woocommerce ) for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
6.1
Affected:
up to 2.1
Fixed in:
2.2
Disclosed:
Nov 17, 2021

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 2.2

unknown

The plugin Login/Signup Popup ( Inline Form + Woocommerce ) for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Nov 17, 2021

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 2.2

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Login/Signup Popup plugin (versions <= 2.1).

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Nov 17, 2021

Login/Signup Popup < 1.5 - Missing Authorization

high

The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can successfully...

CVSS:
7.4
Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
May 14, 2020

CVE-2020-36715 on NVD →

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 1.5

unknown

The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can successfully...

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
May 14, 2020

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 1.5

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by NinTechNet in WordPress Login/Signup Popup plugin (versions <= 1.4).

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
May 14, 2020

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 2.2

unknown

The plugin does not escape its tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 2.2
Fixed in:
2.2

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 1.5

unknown

A lack of capability checks and security nonce allows any authenticated user to inject, via the AJAX API, JavaScript code into the plugin&rsquo;s settings and to use it to target the administrator in the backend of WordPress. The vulnerability has been exploited for a couple of days.

Affected:
up to 1.5
Fixed in:
1.5

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 2.4

unknown

The plugin does not have CSRF check when reseting its settings, which could allow attackers to make logged in admins perform such action via a CSRF attack

Affected:
up to 2.4
Fixed in:
2.4

Login &amp; Register Customizer – Popup | Slider | Inline | WooCommerce [easy-login-woocommerce] < 2.8.6

unknown
Affected:
up to 2.8.6
Fixed in:
2.8.6

CVE-2025-1064 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database