Remember Me Controls

Remember Me Controls has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).

The one issue recorded for Remember Me Controls has a vendor fix available, so running the current release closes it.

All of these findings were reported by stealthcopter. Remember Me Controls is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Remember Me Controls vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2024-7415

Remember Me Controls <= 2.0.1 - Unauthenticated Full Path Disclosure

Read the full analysis

Vulnerability Records

1 records
Remember Me Controls banner
Latestv2.1

Remember Me Controls

Scott Reilly

Author

Scott Reilly

4.3(7)
86/100
Last Updated
2024-09-04 (2y ago)
Active Installs
4,000+
Downloads
53,298
Requires WP
5.5+
Requires PHP
0+
Tested up to
WP 6.6.7
Created
2010-09-27 (16y ago)

Take control of the “Remember Me” login feature for WordPress by having it enabled by default, customize how long users are remembered, or disable this built-in feature by default. For those unfamiliar, “Remember Me” is a checkbox present when logging into WordPress. If checked, WordPress will remember the login session for 14 days. If unchecked, the login session will be remembered for only 2 days. Once a login session expires, WordPress will require you to log in again if you wish to continue using the admin section of the site. This plugin provides three primary controls over the behavior of the “Remember Me” feature: Automatically check “Remember Me” : The ability to have the “Remember Me” checkbox automatically checked when the login form is loaded (it isn’t checked by default). Customize the duration of the “Remember Me” : The ability to customize how long WordPress will remember a login session when “Remember Me” is checked, either forever or a customizable number of hours. Disable “Remember Me” : The ability to completely disable the feature, preventing the checkbox from appearing and restricting all login sessions to 2 days. NOTE: WordPress remembers who you are based on cookies stored in your web browser. If you use a different web browser, clear your cookies, use a browser on a different machine, or uninstall/reinstall (and possibly even just restarting) your browser then you will have to log in again since WordPress will not be able to locate the cookies needed to identify you. Compatibility Other than the plugins listed below, compatibility has not been tested or attempted for any other third-party plugins that provide their own login widgets or login handling. Special handling has been added to provide compatibility with the following plugins: BuddyPress (in particular, its “Log in” widget) Sidebar Login Login Widget With Shortcode Links: Plugin Homepage | Plugin Directory Page | GitHub | Author Homepage

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C