Customize Login Image [customize-login-image] < 3.5.3
unknown
[en] A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Mar 9, 2022
CVE-2021-33851 on NVD →
Customize Login Image <= 3.4 - Cross-Site Scripting
medium
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.
- CVSS:
- 5.4
- Affected:
- up to 3.4
- Fixed in:
- 3.5
- Disclosed:
- Dec 2, 2021
CVE-2021-33851 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database