PatchSiren

LoginPress CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH LoginPress CVE published 2026-07-10

CVE-2026-12598

The LoginPress Pro plugin for WordPress has an authentication bypass vulnerability in versions up to and including 6.2.3 via the Spotify Social Login addon. This vulnerability allows unauthenticated attackers to log in as any existing WordPress user, including Administrators, by registering a Spotify account using the targeted user's email address and authenticating via the Spotify provider. The vulnerabi [truncated]

HIGH LoginPress CVE published 2026-07-10

CVE-2026-12597

The LoginPress Pro plugin for WordPress has an authentication bypass vulnerability due to the GitHub OAuth callback implementation. This CVE was published on 2026-07-10T00:16:32.603Z and has not been modified since then. The NVD entry is currently Deferred. The vulnerability exists in the loginpress_on_github_login() function, which trusts the first element (profile[0]['email']) of the array returned by G [truncated]

HIGH LoginPress CVE published 2026-07-10

CVE-2026-12595

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /users/@me endpoint without ever checking that the profile's verified flag is true, then directly maps that email [truncated]

CRITICAL LoginPress CVE published 2026-06-17

CVE-2026-49058

A critical vulnerability, CVE-2026-49058, was found in the LoginPress Pro plugin (versions <= 6.2.2). This vulnerability allows for unauthenticated privilege escalation, posing a significant risk to WordPress installations using the affected plugin. The CVSS score of 9.8 indicates a high severity level. Users of the LoginPress Pro plugin should take immediate action to mitigate this vulnerability.