plugin

Feather Login Page Vulnerabilities

12 known security issues reported for the Feather Login Page WordPress plugin. Most recent disclosed Dec 22, 2025.

2 high 4 medium

Running Feather Login Page on your site? Check whether your installed version is affected.

Scan your site free

Login | Login Page | Login Logo | Rename Login Page | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha [feather-login-page] <= 1.1.7 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page allows Cross Site Request Forgery.This issue affects Feather Login Page: from n/a through 1.1.7.

Affected:
up to 1.1.7
Fix:
No patched version reported
Disclosed:
Dec 22, 2025

CVE-2025-62107 on NVD →

Feather Login Page <= 1.1.7 - Cross-Site Request Forgery

medium

The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.7. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they ca...

CVSS:
4.3
Affected:
up to 1.1.7
Fix:
No patched version reported
Disclosed:
Nov 5, 2025

CVE-2025-62107 on NVD →

Login | Login Page | Login Logo | Rename Login Page | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha [feather-login-page] < 1.1.6 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page.This issue affects Feather Login Page: from n/a through 1.1.5.

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Apr 15, 2024

CVE-2024-31923 on NVD →

Feather Login Page <= 1.1.5 - Cross-Site Request Forgery via saveData()

medium

The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on the saveData() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request gran...

CVSS:
4.3
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Apr 10, 2024

CVE-2024-31923 on NVD →

Login | Login Page | Login Logo | Rename Login Page | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha [feather-login-page] < 1.1.4 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Nov 6, 2023

CVE-2023-46777 on NVD →

Feather Login Page <= 1.1.3 - Cross-Site Request Forgery

medium

The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing nonce validation on the deleteUser() function. This makes it possible for unauthenticated attackers to delete users via a forged request granted they can trick a site a...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Oct 26, 2023

CVE-2023-46777 on NVD →

Login | Login Page | Login Logo | Rename Login Page | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha [feather-login-page] >= 1.0.7 - <= 1.1.1 (closed)

unknown

[en] The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions starting from 1.0.7 up to, and including, 1.1.1. This is due to missing nonce validation in the 'createTempAccountLink' function. This makes it possible for unauthenticated attackers to create a new user with admini...

Affected:
1.0.7 – 1.1.1
Fixed in:
1.1.1
Disclosed:
May 31, 2023

CVE-2023-2549 on NVD →

Login | Login Page | Login Logo | Rename Login Page | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha [feather-login-page] >= 1.0.7 - <= 1.1.1 (closed)

unknown

[en] The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteUser' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to dele...

Affected:
1.0.7 – 1.1.1
Fixed in:
1.1.1
Disclosed:
May 31, 2023

CVE-2023-2547 on NVD →

Login | Login Page | Login Logo | Rename Login Page | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha [feather-login-page] >= 1.0.7 - <= 1.1.1 (closed)

unknown

[en] The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, t...

Affected:
1.0.7 – 1.1.1
Fixed in:
1.1.1
Disclosed:
May 31, 2023

CVE-2023-2545 on NVD →

Feather Login Page 1.0.7 - 1.1.1 - Cross-Site Request Forgery to Privilege Escalation

high

The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions starting from 1.0.7 up to, and including, 1.1.1. This is due to missing nonce validation in the 'createTempAccountLink' function. This makes it possible for unauthenticated attackers to create a new user with administrat...

CVSS:
8.8
Affected:
1.0.7 – 1.1.1
Fixed in:
1.1.2
Disclosed:
May 30, 2023

CVE-2023-2549 on NVD →

Feather Login Page 1.0.7 - 1.1.1 - Missing Authorization to Authentication Bypass and Privilege Escalation

high

The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to acc...

CVSS:
8.1
Affected:
1.0.7 – 1.1.1
Fixed in:
1.1.2
Disclosed:
May 30, 2023

CVE-2023-2545 on NVD →

Feather Login Page 1.0.7 - 1.1.1 - Missing Authorization to Non-Arbitrary User Deletion

medium

The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteUser' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete th...

CVSS:
5.4
Affected:
1.0.7 – 1.1.1
Fixed in:
1.1.2
Disclosed:
May 30, 2023

CVE-2023-2547 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database