User Login History <= 2.1.7 - Authenticated (Administrator+) SQL Injection via 'blog_id' Parameter
medium
The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including, 2.1.7. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated a...
- CVSS:
- 4.9
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.8
- Disclosed:
- Aug 15, 2026
CVE-2026-2283 on NVD →
User Login History <= 2.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The User Login History plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...
- CVSS:
- 6.4
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- May 7, 2025
CVE-2025-47676 on NVD →
User Login History [user-login-history] <= 2.1.6 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faiyaz Alam User Login History allows Stored XSS. This issue affects User Login History: from n/a through 2.1.6.
- Affected:
- up to 2.1.6
- Fix:
- No patched version reported
- Disclosed:
- May 7, 2025
CVE-2025-47676 on NVD →
User Login History <= 1.7.0 - SQL Injection via Order By
high
The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append...
- CVSS:
- 8.8
- Affected:
- 1.7.0 – 1.7.0
- Fixed in:
- 1.7.1
- Disclosed:
- Mar 16, 2019
User Login History <= 1.7.0 - SQL Injection via OrderBy
high
The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append...
- CVSS:
- 8.8
- Affected:
- 1.7.0 – 1.7.0
- Fixed in:
- 1.7.1
- Disclosed:
- Mar 16, 2019
User Login History [user-login-history] < 1.7.1
unknown
The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append...
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Mar 16, 2019
User Login History [user-login-history] < 1.7.1
unknown
The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append...
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Mar 16, 2019
User Login History Plugin <= 1.5.2 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, (3) user_id, (4) username, (5) country_name, (6) browser, (7) operating_system, or (8) ip_address parameter t...
- CVSS:
- 6.1
- Affected:
- up to 1.6
- Fixed in:
- 1.6
- Disclosed:
- Oct 26, 2017
CVE-2017-15867 on NVD →
User Login History [user-login-history] < 1.6
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, (3) user_id, (4) username, (5) country_name, (6) browser, (7) operating_system, or (8) ip_address parame...
- Affected:
- up to 1.6
- Fixed in:
- 1.6
- Disclosed:
- Oct 24, 2017
CVE-2017-15867 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database