LoginWP (Formerly Peter's Login Redirect)

LoginWP (Formerly Peter's Login Redirect) has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2021; all 3 are fixed as of September 2026. Their average CVSS score is 7.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Cross-Site Request Forgery (CSRF).

Every one of the 3 issues recorded for LoginWP (Formerly Peter's Login Redirect) has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by ZhongFu Su. LoginWP (Formerly Peter's Login Redirect) is installed on roughly 90,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
7.0/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all LoginWP (Formerly Peter's Login Redirect) vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2019-15115

LoginWP <= 2.9.1 - Multiple Cross-Site Request Forgery vulnerabilities

Read the full analysis

Vulnerability Records

3 records
LoginWP (Formerly Peter's Login Redirect) banner
Latestv3.0.9.0

LoginWP (Formerly Peter's Login Redirect)

Marketing Fire

Author

Marketing Fire

4.8(503)
96/100
Last Updated
2026-09-11 (2d ago)
Active Installs
90,000+
Downloads
2,834,117
Requires WP
5.6+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2008-09-10 (18y ago)

LoginWP (formerly Peter’s Login Redirect) lets you define a set of redirect rules for specific users, users with specific roles, users with specific capabilities, and a blanket rule for all other users. Also, set a redirect URL for post-registration. You can use the following placeholders in your URLs so that the system will build a dynamic URL upon each login: {{username}}, {{user_slug}}, {{website_url}}. Upgrade to LoginWP PRO to redirect users to the current page they are logging in from or back to the previous (or referrer) page after login using {{current_page}} and {{previous_page}} placeholders. Learn more You can add your own code logic before and between any of the plugin’s normal redirect checks if needed. See our documentation. Some examples include: redirecting the user based on their IP address and redirecting users to a special page on the first login. Website | Documentation | Support Pro Integrations This is the lite version that works with the default WordPress login page and limited other user registration and login form plugins. Upgrade to Pro to avail the support for the following features and plugins. Redirect After First Login WooCommerce Gravity Forms WPForms LearnDash Uncanny Toolkit LifterLMS Tutor LMS ProfilePress MemberPress MemberMouse LearnPress Easy Digital Downloads Restrict Content Pro Ultimate Member WP User Manager WP User Frontend Paid Memberships Pro WishList Member Theme My Login User Registration (WPEverest) Elementor Login Form BuddyBoss Theme Login/Registration Form Divi Theme Login/Registration Form

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C