plugin

Customize Login Image Vulnerabilities

2 known security issues reported for the Customize Login Image WordPress plugin. Most recent disclosed Mar 9, 2022.

1 medium

Running Customize Login Image on your site? Check whether your installed version is affected.

Scan your site free

Customize Login Image [customize-login-image] < 3.5.3

unknown

[en] A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Mar 9, 2022

CVE-2021-33851 on NVD →

Customize Login Image <= 3.4 - Cross-Site Scripting

medium

A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.

CVSS:
5.4
Affected:
up to 3.4
Fixed in:
3.5
Disclosed:
Dec 2, 2021

CVE-2021-33851 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database