Executive brief
LoginPress Pro is a WordPress plugin used to customize and secure website login pages. A critical vulnerability allows unauthenticated attackers to gain administrative privileges on the site. This could lead to a total takeover of the website, allowing attackers to steal customer data, modify content, or install malicious software.
Technical details
A privilege escalation vulnerability exists in LoginPress Pro due to incorrect privilege assignment (CWE-266). The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining full administrative control over the affected WordPress installation. The attack can be executed over the network without any user interaction or prior authentication. The vulnerability is addressed in version 6.2.3.
Affected products
- LoginPress LoginPress Pro <= 6.2.2
Timeline
- 2026-05-31: other: Reported by researcher wackydawg
- 2026-06-08: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: CVE published and NVD record created
- 2026-06-17: patched: Patch confirmed available in version 6.2.3