Impact
A missing authorization check in the WP Customize Login Page plugin allows callers to reach functionality that should be guarded by role-based access control. The flaw enables an attacker to alter login page settings or retrieve sensitive configuration data, potentially compromising the security posture of the site or facilitating further attacks.
Affected Systems
WordPress sites running Carlo La Pera WP Customize Login Page plugin version 1.6.5 or earlier are affected. The vulnerability exists in the plugin codebase across all WordPress installations that have the described versions installed.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity, and an EPSS score of less than 1 %, showing that active exploitation is unlikely but not impossible. It is not listed in the CISA KEV catalog. The likely attack vector is remote through a web request to the plugin’s administrative endpoint; an authenticated user or anyone able to send crafted requests could exploit the flaw if the access restrictions are bypassed.
OpenCVE Enrichment
EUVD