CVE-2026-66594: WordPress WordPress Persistent Login plugin <= 3.1.0 - SQL Injection vulnerability
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Persistent Login Pluginto a version that resolves this vulnerability.Fixed in 3.1.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs a WordPress account with Subscriber-level privileges. The CVSS vector indicates the attack can be performed over the network without user interaction and with low attack complexity.
What is the likely security impact if exploitation succeeds?
The supplied CVSS vector rates confidentiality impact as high and availability impact as low. It indicates no direct integrity impact.
Which sites should be prioritized for remediation?
Sites using the WordPress Persistent Login plugin at version 3.1.0 or earlier should be prioritized, particularly where Subscriber accounts can be created or obtained by untrusted users.