Input validation vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha 1.1.1

The Feather Login Page is a plugin for the WordPress website builder. A vulnerability has been discovered in versions of this plugin between 1.0.7 and 1.1.1. It is possible for someone who is not logged in to a WordPress website to create a new user with administrator privileges. To do this, they need to trick an administrator into clicking a link. They can use a different vulnerability to get the login link for the new user or send a password reset to the user’s email address.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.