Impact
The vulnerability is a Cross‑Site Request Forgery that permits an attacker to alter the settings of the Customize Login Page plugin through a forged request. This can modify how the login page behaves or appears, potentially undermining authentication controls or exposing sensitive configuration data. The weakness identified is CWE‑352.
Affected Systems
The issue affects the AboZain Albanna Customize Login Page plugin on all installation versions up to and including 1.1. No newer versions have been listed as vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk and the EPSS score is below 1%, suggesting a low likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. The most likely attack vector is a CSRF request delivered from a malicious site while a legitimate user, logged into WordPress and with permission to change plugin settings, visits the site. If successful, the attacker can change plugin configuration at the victim’s discretion.
OpenCVE Enrichment
EUVD