VYPR
Medium severity5.3NVD Advisory· Published Apr 24, 2025· Updated Apr 23, 2026

CVE-2025-46485

CVE-2025-46485

Description

Missing Authorization vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Customize Login Page: from n/a through <= 1.6.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The WP Customize Login Page plugin versions ≤1.6.5 have a missing authorization vulnerability allowing unauthenticated access to restricted functionality.

The WP Customize Login Page plugin for WordPress suffers from a missing authorization vulnerability in versions up to and including 1.6.5. The root cause is the absence of proper capability checks or nonce validation in certain functions, which should have restricted access to administrative actions. This flaw is classified as a broken access control issue, as described in the Patchstack advisory [1].

An unauthenticated attacker can exploit this vulnerability by sending crafted requests to the affected plugin endpoints without needing any authentication or prior knowledge. The attack surface is broad because the plugin is widely used, and the vulnerability can be triggered remotely over HTTP. No special network position or user interaction is required [1].

Successful exploitation allows an attacker to access functionality that is normally reserved for higher-privileged users, such as modifying login page settings, injecting malicious content, or altering site appearance. This could lead to further compromise, including phishing attacks or defacement. The vulnerability is noted to be used in mass-exploit campaigns targeting thousands of websites [1].

As a mitigation, users should immediately update the WP Customize Login Page plugin to version 1.6.6 or later, which contains the necessary authorization checks. If updating is not possible, contacting a hosting provider or web developer for assistance is recommended. No workaround is available [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.