WP Custom Admin Login Page Logo Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Custom Admin Login Page Logo plugin for WordPress, affecting all versions through 1.4.8.4. The vulnerability arises from inadequate nonce validation in the wpclpl_save function, allowing unauthenticated attackers to alter the plugin's settings by sending a forged request, provided they can deceive a site administrator into clicking a link.
Impact
Exploitation of this vulnerability allows for Cross-Site Request Forgery, enabling attackers to manipulate the plugin's settings on behalf of an administrator.
Added: Nov 11, 2025, 4:41 AM
Updated: Nov 11, 2025, 4:41 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
6.4remediation
0.0relevance
1.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
