Description
Cross-Site Request Forgery (CSRF) vulnerability in NiteoThemes CLP – Custom Login Page by NiteoThemes clp-custom-login-page allows Cross Site Request Forgery.This issue affects CLP – Custom Login Page by NiteoThemes: from n/a through <= 1.5.5.
Published: 2025-04-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw in NiteoThemes' CLP – Custom Login Page plugin, allowing an attacker to trick a logged‑in user into performing unintended actions on the WordPress site. The plugin fails to validate or require a CSRF token for key administrative operations, granting attackers the ability to change login settings, alter site behavior, or submit content without the user’s knowledge. This weakness is mapped to CWE‑352 and carries a CVSS score of 4.3, indicating a moderate impact.

Affected Systems

Affected products include the NiteoThemes CLP – Custom Login Page plugin for WordPress, specifically any release up through version 1.5.5. No other plugin versions are listed as vulnerable in the official advisories, so upgrades beyond 1.5.5 are presumed safe.

Risk and Exploitability

The risk of exploitation is moderate in severity but low in likelihood (EPSS < 1 %). Attackers would need to target a site that still runs the vulnerable plugin and have a victim authenticated against it, sending a crafted request that the plugin accepts without nonce verification. Because the vulnerability is not in the CISA KEV catalog and the exploit requires user interaction within the browser, the threat landscape remains limited but still measurable. Administrators should treat the plugin as a medium‑risk asset pending remediation.

Generated by OpenCVE AI on May 1, 2026 at 02:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the NiteoThemes CLP – Custom Login Page plugin to the latest available release, which removes the CSRF validation flaw.
  • If an immediate upgrade is not possible, deactivate or uninstall the plugin to eliminate the attack surface.
  • Apply a site‑wide Web Application Firewall rule or use a security plugin to block unexpected POST requests directed at the plugin’s admin URLs and enforce strict user authentication policies.

Generated by OpenCVE AI on May 1, 2026 at 02:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9258 Cross-Site Request Forgery (CSRF) vulnerability in NiteoThemes CLP – Custom Login Page by NiteoThemes allows Cross Site Request Forgery. This issue affects CLP – Custom Login Page by NiteoThemes: from n/a through 1.5.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in NiteoThemes CLP – Custom Login Page by NiteoThemes allows Cross Site Request Forgery. This issue affects CLP – Custom Login Page by NiteoThemes: from n/a through 1.5.5. Cross-Site Request Forgery (CSRF) vulnerability in NiteoThemes CLP – Custom Login Page by NiteoThemes clp-custom-login-page allows Cross Site Request Forgery.This issue affects CLP – Custom Login Page by NiteoThemes: from n/a through <= 1.5.5.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 01 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in NiteoThemes CLP – Custom Login Page by NiteoThemes allows Cross Site Request Forgery. This issue affects CLP – Custom Login Page by NiteoThemes: from n/a through 1.5.5.
Title WordPress CLP – Custom Login Page by NiteoThemes plugin <= 1.5.5 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.457Z

Reserved: 2025-04-01T13:19:46.768Z

Link: CVE-2025-31769

cve-icon Vulnrichment

Updated: 2025-04-01T20:32:12.787Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:13.880

Modified: 2026-04-23T15:28:15.343

Link: CVE-2025-31769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:30:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)