Inactive Logout
Inactive Logout has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.4 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Missing Authorization.
Every one of the 3 issues recorded for Inactive Logout has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Inactive Logout is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-11922Inactive Logout <= 3.5.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Inactive Logout
Author
Deepen Bajracharya
Protect your WordPress users’ sessions from prying eyes and snoopers! The Inactive Logout plugin automatically terminates idle user sessions, safeguarding your site if users leave their sessions unattended. A simple plugin which is easy to configure and use. After installing and activating it, just set the idle timeout from the plugin settings. From then on, any unattended idle WordPress sessions will be automatically terminated. You can also display a custom message to users, warning them that their session is about to end. Try it out ==> Demo FEATURES:. Change idle timeout time. Count down of 10 seconds before actual logout. You can remove this feature if you dont want it. Add only Wake Up! message where user will not logout but instead a wakeup message will be shown upon inactive. Custom Popup Message. Show idle message for non authenticated users or redirect them. Concurrent user logouts. Toast notification on Logout. Redirect to a Different Page instead of Popup box. Create a page such as timeout page and add your content there by creating a blank template or style it as you wish according to your theme. Multiple User Role Configurations for individual timeout and session logout redirects. Logout to custom page or existing page. Clean UI WooCommerce Supported. Multisite Support: Override all sites with one setting. EXTEND OTHER FEATURES: Few of the key features to Inactive Logout Pro: Auto browser close logout after defined duration. Fully functional multi-tab support. User Based Logout Track Visitors based on (Login time, logout time, browser, online status, session duration, role, os, IP) Force Logout All Users Logout Specific User(s) Bulk Logout Users Concurrent Login Limits. Last Login Activity Override Multiple Login priority User Lock whenever certain limit login has been reached. Track user login sessions. Logout redirects. Login redirects. Email notification and email template overrides for Locked concurrent session. Disable inactive logout for specified pages according to your need. Check this Documentation for additional post type support. Disable native wordpress login popup after logout Modal Customizer **See the Inactive Logout homepage for further information. Please consider giving a 5 star thumbs up if you found this useful.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C