Custom Login Page Styler <= 7.1.1 - Missing Authorization to Authenticated (Subsciber+) Log Deletion and Session Termination
medium
The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the lps_handle_delete_all_logs(), lps_handle_delete_login_log(), and lps_handle_...
- CVSS:
- 4.3
- Affected:
- up to 7.1.1
- Fixed in:
- 7.1.2
- Disclosed:
- Jan 30, 2025
CVE-2024-13530 on NVD →
ALL In One Custom Login Page <= 7.1.1 - Missing Authorization to Authenticated (Subscriber+)Privilege Escalation
high
The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Temporary admin login access , Rename login , Login customizer, Hide wp-login – Limit Login Attempts – Locked Site plugin for WordPress is vulnerable to privilege escalation due to a missing capability check...
- CVSS:
- 8.8
- Affected:
- up to 7.1.1
- Fixed in:
- 7.1.2
- Disclosed:
- Dec 23, 2024
CVE-2024-12594 on NVD →
Login Page Styler <= 6.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Login Page Styler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbit...
- CVSS:
- 4.4
- Affected:
- up to 6.2
- Fixed in:
- 6.2.5
- Disclosed:
- Apr 19, 2023
CVE-2022-46861 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database