cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foradmin-custom-login admin-custom-login

Direction: ascending
Jun 07, 2024

Admin Custom Login # CVE-2021-34628

CVE, Research URL

CVE-2021-34628

Application

Admin Custom Login

Date
Aug 03, 2021
Research Description
The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-setting/Login-form-background.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.7.
Affected versions
max 3.2.8.
Status
vulnerable
Jun 16, 2026

Admin Custom Login # a4505af5-ba74-4074-8ad8-3ef4dd0df6a5

Application

Admin Custom Login

Date
-
Research Description
Admin Custom Login [admin-custom-login] < 2.4.8 Admin Custom Login &lt;= 2.4.7.1 - Authenticated Stored Cross-Site Scripting (XSS) The Admin Custom Login WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.
Affected versions
max 2.4.8.
Status
vulnerable

Admin Custom Login # 5c6d99f4286a034c6e844d06e8fc7adc3ad35074

Application

Admin Custom Login

Date
Mar 01, 2017
Research Description
Admin Custom Login [admin-custom-login] < 2.4.8 Admin Custom Login <= 2.4.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting The Admin Custom Login plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via the ‘logo_url’ parameter in versions before 2.4.8 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for unauthenticated attackers to inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.4.8.
Status
vulnerable
Aug 18, 2026

Admin Custom Login # CVE-2026-2487

CVE, Research URL

CVE-2026-2487

Application

Admin Custom Login

Date
Aug 16, 2026
Research Description
The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 3.6.5.
Status
vulnerable