Login-Logout
Login-Logout has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Login-Logout has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Que Thanh Tuan - Blue Rock. Login-Logout is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.5.20.
CVE-2025-53467Login-Logout <= 3.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Login-Logout
Author
webvitalii
Advanced iFrame Pro Login-Logout Donate GitHub “Login-Logout” plugin adds widget with login or logout link. Also can be shown register or site-admin link. It is the replacement of the default Meta widget. If user is not logged in there are such links: login (after login action user will return to previous page); register (if user can register) (if checkbox is active); If user is logged in there are such links: welcome text with link to user profile (if checkbox is active); logout (after logout action user will return to previous page); site admin (if checkbox is active);
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C