Input validation vulnerability in LoginPress | wp-login Custom Login Page Customizer 3.3.1

A popular plugin for customizing the login page on WordPress websites, called LoginPress, has a security flaw that allows attackers to make changes to the site without proper authorization. This can happen if a site administrator is tricked into clicking on a malicious link. By exploiting this vulnerability, attackers can make themselves an administrator account and gain full control of the site. In order for this to work, the plugin needs to be in a specific mode.

Detected in:

LoginPress | wp-login Custom Login Page Customizer fixed vulnerable versions: >= * <= 3.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.