Vulnerabilities and security researches forlogin-customizer login-customizer
Direction: descendingFeb 27, 2026
Custom Login Page Customizer # CVE-2025-14975
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 29, 2026
- Research Description
- The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account
- Affected versions
-
max 2.5.4.
- Status
-
vulnerable
Nov 15, 2024
Custom Login Page Customizer # CVE-2022-4974
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 16, 2024
- Research Description
- The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 2.1.8.
- Status
-
vulnerable
Jun 07, 2024
Custom Login Page Customizer # 0a1a4f6ae62d8f362f6160e687ffc674dc5362bb
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 28, 2022
- Research Description
- Custom Login Page Customizer [login-customizer] < 2.1.8 WordPress Custom Login Page Customizer plugin <= 2.1.7 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Custom Login Page Customizer plugin (versions <= 2.1.7).
- Affected versions
-
max 2.1.8.
- Status
-
vulnerable