VYPR
Medium severity6.5NVD Advisory· Published Dec 18, 2025· Updated Apr 28, 2026

CVE-2025-49902

CVE-2025-49902

Description

Missing Authorization vulnerability in A WP Life Login Page Customizer – Customizer Login Page, Admin Page, Custom Design customizer-login-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Page Customizer – Customizer Login Page, Admin Page, Custom Design: from n/a through <= 2.1.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A broken access control flaw in the Login Page Customizer plugin up to v2.1.1 allows unauthenticated attackers to exploit incorrectly configured access controls, leading to unauthorized actions.

Vulnerability

Overview The vulnerability is a Missing Authorization issue in the WordPress plugin Login Page Customizer – Customizer Login Page, Admin Page, Custom Design (slug: customizer-login-page), versions n/a through 2.1.1. It arises from incorrectly configured access control security levels, allowing exploitation of the broken access control. [1]

Exploitation

Conditions The flaw does not require authentication, making it remotely exploitable by any unauthenticated attacker. Attackers can leverage this to perform actions that should be restricted to higher-privileged users. This type of vulnerability is commonly used in mass-exploitiate mass-exploit campaigns targeting large numbers of websites. [1]

Potential

Impact An attacker exploiting this missing authorization can access or modify plugin settings, potentially altering custom login page designs or gaining elevated privileges within the WordPress context. Although the CVSS v3 score is 6.5 (Medium), the actual risk is elevated due to the ease of exploitation and availability of public exploit details. [1]

Mitigation

The vendor has released version 2.1.2, which patches the broken access controls. Users are strongly advised to update immediately to patched version. Patchstack also offers a mitigation rule to block attacks until the plugin is updated. [1]

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.