CVE Database /
CVE-2022-1589
CVE · High
CVE-2022-1589 — All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 1.1.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-1589
|
All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 1.1.0 |
Cross-Site Request Forgery (CSRF) |
High
7.5
|
< 1.1.0
|
1.1.0 |
2022-05-09 |
—
|
CVE-2022-1589
The Change wp-admin login plugin versions prior to 1.1.0 contained authorization and CSRF protection flaws in its settings update functionality. These vulnerabilities could be exploited by unauthenticated attackers to modify plugin settings either through direct requests or by manipulating authenticated users via cross-site request forgery attacks. Both attack vectors posed a risk to the plugin's configuration integrity.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings