plugin

User Login History Vulnerabilities

9 known security issues reported for the User Login History WordPress plugin. Most recent disclosed Aug 15, 2026.

2 high 3 medium

Running User Login History on your site? Check whether your installed version is affected.

Scan your site free

User Login History <= 2.1.7 - Authenticated (Administrator+) SQL Injection via 'blog_id' Parameter

medium

The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including, 2.1.7. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated a...

CVSS:
4.9
Affected:
up to 2.1.7
Fixed in:
2.1.8
Disclosed:
Aug 15, 2026

CVE-2026-2283 on NVD →

User Login History <= 2.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The User Login History plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...

CVSS:
6.4
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
May 7, 2025

CVE-2025-47676 on NVD →

User Login History [user-login-history] <= 2.1.6 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faiyaz Alam User Login History allows Stored XSS. This issue affects User Login History: from n/a through 2.1.6.

Affected:
up to 2.1.6
Fix:
No patched version reported
Disclosed:
May 7, 2025

CVE-2025-47676 on NVD →

User Login History <= 1.7.0 - SQL Injection via Order By

high

The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append...

CVSS:
8.8
Affected:
1.7.0 – 1.7.0
Fixed in:
1.7.1
Disclosed:
Mar 16, 2019

User Login History <= 1.7.0 - SQL Injection via OrderBy

high

The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append...

CVSS:
8.8
Affected:
1.7.0 – 1.7.0
Fixed in:
1.7.1
Disclosed:
Mar 16, 2019

User Login History [user-login-history] < 1.7.1

unknown

The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append...

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Mar 16, 2019

User Login History [user-login-history] < 1.7.1

unknown

The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append...

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Mar 16, 2019

User Login History Plugin <= 1.5.2 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, (3) user_id, (4) username, (5) country_name, (6) browser, (7) operating_system, or (8) ip_address parameter t...

CVSS:
6.1
Affected:
up to 1.6
Fixed in:
1.6
Disclosed:
Oct 26, 2017

CVE-2017-15867 on NVD →

User Login History [user-login-history] < 1.6

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, (3) user_id, (4) username, (5) country_name, (6) browser, (7) operating_system, or (8) ip_address parame...

Affected:
up to 1.6
Fixed in:
1.6
Disclosed:
Oct 24, 2017

CVE-2017-15867 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database