VYPR

Admin Custom Login

by WordPress

CVEs (2)

  • CVE-2021-34628HigAug 2, 2021
    risk 0.57cvss 8.8epss 0.01

    The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-setting/Login-form-background.php file which allows attackers to inject arbitrary web scripts, in versions up to and including…

  • CVE-2026-2487MedAug 16, 2026
    risk 0.29cvss 4.4epss 0.00

    The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…