Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total6
Critical0
High2
Medium4
Reset
Showing 1-6 of 6 records
Threat Entry Updated 2026-01-29

CVE-2025-14975 - Custom Login Page Customizer Plugin

The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

PLUGIN Custom Login Page Customizer

CVE-2025-14975

HIGH CVSS 8.1 2026-01-29
Threat Entry Updated 2025-03-14

CVE-2025-1764 - Custom Login Page Customizer Plugin

The LoginPress | wp-login Custom Login Page Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.1. This is due to missing or incorrect nonce validation on the 'custom_plugin_set_option' function. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This can be leveraged to update the default role for registration to administrator and enable user…

PLUGIN Custom Login Page Customizer

CVE-2025-1764

HIGH CVSS 7.5 2025-03-14
Threat Entry Updated 2024-11-21

CVE-2024-9371 - Custom Login Page Customizer Plugin

The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.19. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Custom Login Page Customizer

CVE-2024-9371

MEDIUM CVSS 6.1 2024-11-21
Threat Entry Updated 2024-11-21

CVE-2024-6554 - Custom Login Page Customizer Plugin

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.18. This is due the plugin utilizing composer without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Custom Login Page Customizer

CVE-2024-6554

MEDIUM CVSS 5.3 2024-07-11
Threat Entry Updated 2024-11-21

CVE-2024-5191 - Custom Login Page Customizer Plugin

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all versions up to, and including, 3.4.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Custom Login Page Customizer

CVE-2024-5191

MEDIUM CVSS 6.4 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2022-0347 - Custom Login Page Customizer Plugin

The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

PLUGIN Custom Login Page Customizer

CVE-2022-0347

MEDIUM CVSS 6.1 2022-03-07
Scroll to top