Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting
mediumThe Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, Link Color) in versions up to and including 1.0.3. This is due to insufficient input sanitization of the color option values (they were registered w...
- CVSS:
- 4.4
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Jun 1, 2026