Login Widget With Shortcode

Login Widget With Shortcode has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2024; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 7.1 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Open Redirect.

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2024.

2 independent researchers contributed these findings, one record each. Login Widget With Shortcode is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all Login Widget With Shortcode vulnerabilities before they are exploited.

Most severe open issueCVSS 6.1CVE-2024-54255

Login Widget With Shortcode <= 6.1.2 - Open Redirect

Read the full analysis

Vulnerability Records

2 records
Login Widget With Shortcode banner
Latestv6.1.3

Login Widget With Shortcode

aviplugins.com

Author

aviplugins.com

3.8(29)
76/100
Last Updated
2026-07-11 (2mo ago)
Active Installs
5,000+
Downloads
471,522
Requires WP
2.0.2+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2014-02-12 (13y ago)

This is a simple login form in the widget. Compatible with WordPress Multisite Installation. Use this shortcode [login_widget] to use login form in your pages/ posts. Just install the plugin and add the login widget in the sidebar. Change some &#8216;optional’ settings in Login Widget Settings (admin panel left side menu) and you are good to go. Add CSS as you prefer because the form structure is really very simple. Use this shortcode [forgot_password] in your page to display the forgot password form. Forgot password link can be added to login widget from plugin settings page. Login form is responsive. Plugin is compatible with WPML plugin. You can check the compatibility at wpml.org. Other Optional Options Add CAPTCHA security in admin and frontend login forms. Login Logs are stored in database ( IP, login status, login time ). PRO version has options to block IPs after certain numbers of wrong login attempts. You can choose the redirect page after login. It can be a page or a custom URL. Choose redirect page after logout. Choose user profile page. Easy CSS implementation from admin panel. Social Login No Setup The plugin supports login with 30+ sites. The most important part is that it requires no Setups, no Maintanance, no need to create any APPs, APIs, Client Ids, Client Secrets or anything. Get it for USD 3.00. Supported sites are listed below. Google YouTube Google Drive Gmail Twitter LinkedIn PayPal Yahoo Microsoft WordPress Amazon Github Tumblr Vimeo Reddit Dribbble Twitch Medium Discord Line Stack Exchange Stack Overflow Disqus Blogger Meetup Foursquare Yandex VKontakte Telegram Dropbox Fitbit Slack Deviantart Mailchimp Skype Click here for more details | Click here for Live Demo Post your plugin related queries at https://goplugins.in/support.php

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C