← WordPress Vulnerabilities
WordPress security by component

LoginPress | wp-login Custom Login Page Customizer

LoginPress | wp-login Custom Login Page Customizer is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Mar 14, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: loginpress

CVE-2025-1764: LoginPress | wp-login Custom Login Page Customizer: Cross-site request forgery

LoginPress | wp-login Custom Login Page Customizer is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedMar 14, 2025
Safe version guidanceSee mitigation notes
Safe version
Mar 14, 2025 CVE-2025-1764
LoginPress | wp-login Custom Login Page Customizer: Cross-site request forgery
LoginPress | wp-login Custom Login Page Customizer is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE7.5
NVDPending
Nov 18, 2022 CVE-2022-41839
Loginpress: A security weakness
Loginpress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Mar 07, 2022 CVE-2022-0347
LoginPress | Custom Login Page Customizer: Cross-site scripting
LoginPress | Custom Login Page Customizer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Sep 03, 2019 CVE-2019-15872
Loginpress: SQL injection
Loginpress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Sep 03, 2019 CVE-2019-15871
Loginpress: A security weakness
Loginpress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3