CVE-2026-94081: WordPress WordPress Persistent Login plugin <= 3.1.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Persistent Loginto a version that resolves this vulnerability.Fixed in 3.1.4
Event History
Frequently Asked Questions
Which installations are affected?
WordPress sites using the WordPress Persistent Login plugin version 3.1.3 or earlier are affected.
Does an attacker need an account or administrative access?
No. The vulnerability is unauthenticated and can be exploited over the network without prior privileges.
Is user interaction required for exploitation?
Yes. The CVSS vector indicates user interaction is required, meaning an attacker must cause a user to interact with attacker-controlled content or a crafted request.
How can I determine whether my site is affected?
Check whether the WordPress Persistent Login plugin is installed and identify its installed version. Instances running version 3.1.3 or earlier are in scope.