Simple Login Log
Simple Login Log has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 8.7, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 0 high. 2017 was the busiest year with 2 disclosures.
The most common weakness is SQL Injection, behind 2 of the records (67%). Other recurring categories include Deserialization Of Untrusted Data.
Every one of the 3 issues recorded for Simple Login Log has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Neven Birusk. Simple Login Log is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2017-18514Simple Login Log < 1.1.2 - SQL Injection
Read the full analysisVulnerability Records

Simple Login Log
Author
Joris Le Blansch
Simple log of user logins. Tracks user name, time of login, IP address and browser user agent. Features include: ability to filter by user name, successful/failed logins, month and year; export into CSV file; log auto-truncation; option to record failed login attempts. Translations: German [de_DE] by Philipp Moore Russian [ru_RU] Ukrainian [ua_UA] French [fr_FR] by Mehdi Hamida Author: Max Chirkov Author: Joris Le Blansch Translation If you would like to contribute, the POT file is available in the languages folder. Translation file name convention is sll-{locale}.mo, where {locale} is the locale of your language. Fore example, Russian file name would be sll-ru_RU.po.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C