Login or Logout Menu Item

Login or Logout Menu Item has one disclosed vulnerability in the WordSec catalog, all reported in 2019; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Open Redirect, behind 1 of the records (100%).

The one issue recorded for Login or Logout Menu Item has a vendor fix available, so running the current release closes it.

All of these findings were reported by Jerome Bruandet. Login or Logout Menu Item is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Login or Logout Menu Item vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2019-15820

Login or Logout Menu Item <= 1.1.1 - Unauthenticated Settings Update

Read the full analysis

Vulnerability Records

1 records
Login or Logout Menu Item banner
Latestv1.3.2

Login or Logout Menu Item

cartpauj

Author

cartpauj

4.8(23)
96/100
Last Updated
2026-05-28 (4mo ago)
Active Installs
20,000+
Downloads
263,758
Requires WP
6.0+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2017-10-20 (9y ago)

With this plugin you can easily add a dynamic login/logout menu item to any menu on your WordPress site. The menu item will change based on whether the current user is logged in or logged out. You can also set a specific login page url, login redirect url and a logout redirect url. Thanks to Juliobox for his prior efforts on the BAW Login/Logout Menu plugin which this is derived from CONFIGURE SETTINGS After installing and activating the plugin, you can find the settings in your dashboard under: Settings > Login or Logout Login Page URL – This should be the URL to the page where your users will login at. For most wordpress sites this will be /wp-login.php but if you’re using a membership plugin like MemberPress, it might be something like /login/ instead. Login Redirect URL – This is the URL you would like your users to be redirected to after they’ve successfully logged in. You can set it to / to take them to the home page after logging in. If you’re using a membership plugin like MemberPress, you might want to use /account/ instead. NOTE: Some plugins may override this if they are configured to redirect your users somewhere else during login. Logout Redirect URL – This is the URL you would like your users to be redirected to after they click the Logout link from this menu item. Use a / to redirect them to the home page, or you might want to redirect them back to the login page at /login/ or /wp-login.php etc. ADD ITEM TO MENU In your dashboard visit Appearance > Menus. Then at the top right of that page click the Screen Options button and ensure that Login/Logout checkbox is checked. Then select a menu to edit, or create a new menu if you don’t already have one. In the left sidebar find Login/Logout and click the checkbox next to Login|Logout and then click Add to Menu. You can now drag the menu item wherever you’d like it to appear in your menu. The URL in the menu settings must be left at #lolmiloginout# but you can change the Navigation Label if you’d like it to say something else. Just ensure that the | is there in the label separating the two words. Now save your menu. That’s it! BLOCK EDITOR (NAVIGATION BLOCK) If you’re using the block editor’s Navigation block: Add or edit a Navigation block on your page or in the Site Editor Click the (+) to add a new link In the search field, type “login” or “logout” Select “Login|Logout” from the suggestions The link will automatically show “Login” to logged-out users and “Logout” to logged-in users You can also manually type #lolmiloginout# as the URL if you prefer. Troubleshooting After logging in, menu still shows “Login” or Vice-Versa – This is most commonly caused by caching. If you’re using a caching solution such as Cloudflare, WPRocket, or others, be sure that caching is disabled for logged in users, and disable browser caching options as well. Login is redirecting users somewhere other than my settings – Many times other plugins will have their own login redirect handling which overrides this plugin’s, such as MemberPress for example. In this case, the other plugins will need to be configured to redirect the user where you’d like them to go.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C