Custom Login Page Customizer
cpe:2.3:a:custom_login_page_project:custom_login_page:*:*:*:*:wordpress:*:*
- < 2.5.4
A vulnerability exists in the Custom Login Page Customizer WordPress plugin in versions prior to 2.5.4. The plugin lacks a proper password reset mechanism, allowing unauthenticated users to reset the passwords of any user, including administrators, by simply knowing their usernames. This flaw could be exploited to gain unauthorized access to user accounts.
Exploitation of this vulnerability allows for unauthorized password resets, enabling attackers to gain access to user accounts, including those of administrators.
Users are advised to update the Custom Login Page Customizer WordPress plugin to version 2.5.4 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.