Description
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Published: 2026-08-20
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A SQL injection flaw exists in versions of the WordPress Persistent Login plugin up to 3.1.0, allowing an attacker to inject arbitrary SQL statements through the subscriber interface. This could enable the exfiltration of sensitive data, modification or deletion of user credentials, and may provide a foothold for further exploitation depending on the database configuration and web application context.

Affected Systems

The vulnerability affects the WordPress Persistent Login plugin by lukeseager. All releases dated 3.1.0 or earlier are impacted; any installation of this plugin version requires immediate attention.

Risk and Exploitability

The CVSS score of 8.5 classifies this issue as high severity. The EPSS score is not available, making it difficult to gauge current exploitation prevalence. It is not listed in CISA’s KEV catalog. The likely attack vector is remote, via crafted HTTP requests to the plugin’s subscriber endpoint; an attacker does not need authentication to send the payload.

Generated by OpenCVE AI on August 20, 2026 at 21:05 UTC.

Remediation

Vendor Solution

Update the WordPress WordPress Persistent Login Plugin to the latest available version (at least 3.1.1).


OpenCVE Recommended Actions

  • Update the WordPress Persistent Login plugin to version 3.1.1 or later
  • If the plugin is not essential, disable it to remove the attack surface
  • Implement web application firewall rules that detect and block common SQL injection patterns targeting the plugin’s input fields

Generated by OpenCVE AI on August 20, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Lukeseager
Lukeseager wordpress Persistent Login
Wordpress
Wordpress wordpress
Vendors & Products Lukeseager
Lukeseager wordpress Persistent Login
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Title WordPress WordPress Persistent Login plugin <= 3.1.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Lukeseager Wordpress Persistent Login
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T15:19:16.202Z

Reserved: 2026-07-27T14:00:08.990Z

Link: CVE-2026-66594

cve-icon Vulnrichment

Updated: 2026-08-20T14:18:48.567Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:33.307

Modified: 2026-08-20T16:17:42.547

Link: CVE-2026-66594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:10:02Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')