cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forlogin-customizer login-customizer

Direction: ascending
Jun 07, 2024

Custom Login Page Customizer # 0a1a4f6ae62d8f362f6160e687ffc674dc5362bb

Date
Feb 28, 2022
Research Description
Custom Login Page Customizer [login-customizer] < 2.1.8 WordPress Custom Login Page Customizer plugin <= 2.1.7 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Custom Login Page Customizer plugin (versions <= 2.1.7).
Affected versions
max 2.1.8.
Status
vulnerable
Nov 15, 2024

Custom Login Page Customizer # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 2.1.8.
Status
vulnerable
Feb 27, 2026

Custom Login Page Customizer # CVE-2025-14975

CVE, Research URL

CVE-2025-14975

Date
Jan 29, 2026
Research Description
The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account
Affected versions
max 2.5.4.
Status
vulnerable