Custom Login Page Customizer, CVE-2025-14975
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jan 29, 2026
- Research Description
- The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account
- Affected versions
-
max 2.5.4.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| Order Splitter for WooCommerce (CVE-2025-12075) , Feb 27, 2026 |
| Order Splitter for WooCommerce (CVE-2025-31089) , Apr 03, 2025 |