Theme My Login

Theme My Login has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2026; all 7 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2026 was the busiest year with 3 disclosures.

The most common weakness is Missing Authorization, behind 3 of the records (43%). Other recurring categories include Cross-Site Request Forgery (CSRF), Improper Privilege Management.

Every one of the 7 issues recorded for Theme My Login has a vendor fix available, so running the current release closes all known holes.

7 independent researchers contributed these findings, one record each. Theme My Login is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

7

Get automatic notifications for all Theme My Login vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2014-5155

Theme My Login <= 6.3.9 - Local File Inclusion

Read the full analysis

Vulnerability Records

7 records
Theme My Login banner
Latestv7.2.1

Theme My Login

Jeff Farthing

Author

Jeff Farthing

3.7(460)
74/100
Last Updated
2026-09-04 (9d ago)
Active Installs
50,000+
Downloads
4,406,958
Requires WP
5.4+
Requires PHP
0+
Tested up to
WP 7.1
Created
2009-03-13 (18y ago)

Ever wished that your WordPress login page matched the rest of your site? Your wish has come true! Theme My Login allows you to bypass the default WordPress-branded login page that looks nothing like the rest of your site. Instead, your users will be presented with the login, registration and password recovery pages right within your theme. The best part? It works right out of the box, with no configuration necessary! Take back your login page, WordPress users! Features Have you users log in from the frontend of your site. Have your users register from the frontend of your site. Have your users recover their password from the frontend of your site. Customize the slugs used for login, registration, password recovery and other pages. Allow your users to register with only their email. Allow your users to set their own passwords upon registration. Allow your users to log in using either their email and password, username and password or a combination of the two. Allow your users to be logged in automatically after registration with auto-login. Do More With Extensions Boost your user experience even more with add-on plugins from our extensions catalog. Some of our extensions include: Redirection allows you to redirect your users on login, logout and registration based on their role. Restrictions allows you to restrict posts/pages, widgets and nav menu items based on a users login status and/or role. Profiles lets your users edit their profile from the frontend of your site. Moderation allows you to moderate your users by requiring them to confirm their email or by requiring admin approval. reCAPTCHA enables Google reCAPTCHA support for your registration and login forms. Social allows you to allow your users to log in to your site using their favorite social providers.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C