Login with Cognito

Login with Cognito has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2022; all 3 are fixed as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high. 2022 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Authentication Bypass Using An Alternate Path Or Channel.

Every one of the 3 issues recorded for Login with Cognito has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Login with Cognito is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSHigh
7.1/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Login with Cognito vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8

Login with Cognito <= 1.4.6 - Authentication Bypass

Read the full analysis

Vulnerability Records

3 records
Login with Cognito banner
Latestv1.5.5

Login with Cognito

miniOrange

Author

miniOrange

0.0(0)
0/100
Last Updated
2026-09-02 (11d ago)
Active Installs
80+
Downloads
8,615
Requires WP
5.9+
Requires PHP
0+
Tested up to
WP 7.1
Created
2020-02-13 (7y ago)

WordPress Login with Cognito plugin allows Login ( Single Sign-On ) to WordPress using AWS Cognito account credentials. You can SSO ( Single Sign-on )/Login to your WordPress site with Cognito using this plugin. This plugin uses OAuth protocol to achieve Single Sign-on. It also covers User Authentication with OAuth protocol and allow authorized user to login into WordPress site. Single Sign-On ( SSO ) In simple term, Single Sign-On ( SSO ) means login into 1 site / application using the credentials of another app/site. Example. If you have all your Users/Customers/Members/Employees stored on 1 site(ex. gmail, wordpress, etc.), lets say site A and you want all of them to register/login into your WordPress site say site B. In this scenario, you can register/login all your users of site A into Site B using the login credentials/account of Site A. This is called Single Sign-On or SSO. FEATURES WordPress Login with Cognito supports single sign-on / SSO with Cognito domain. Single Sign On ( SSO ) Grant Support : Standard OAuth 2.0 Grant : Authorization Code Auto Create Users : After SSO, new user automatically gets created in WordPress Account Linking : After user SSO to WordPress, if user already exists in WordPress, then his profile gets updated or it will create a new WordPress User Attribute Mapping : Login with Cognito supports username Attribute Mapping feature to map WordPress user profile username attribute. Login Widget : Use Widgets to easily integrate the login link with your WordPress site Redirect URL after Login : OAuth Login Automatically Redirects user after successful login. USE CASES Easily auto-register users into Cognito Pools from WordPress login forms with our WP Cognito Integration plugin.More Details Use custom login forms and avoid redirecting users to Cognito during SSO with our WP Cognito Integration plugin.More Details Sync membership status updates (upgrade, downgrade, renewal, expiration) to AWS Cognito user profiles.More Details Manage backend authentication via Cognito credentials for your custom designed code.More Details Cognito Integrator enables single-login access across multiple WordPress sites with customizable integration.More Details User verification in Cognito when a user creates an account from the woocommerce checkout page.More Details No SSL restriction Login to WordPress ( WordPress SSO ) using Cognito without having an SSL or HTTPS enabled site.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C