CVE · High

CVE-2022-1589 — All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 1.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-1589 All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 1.1.0 Cross-Site Request Forgery (CSRF) High 7.5 < 1.1.0 1.1.0 2022-05-09

CVE-2022-1589

The Change wp-admin login plugin versions prior to 1.1.0 contained authorization and CSRF protection flaws in its settings update functionality. These vulnerabilities could be exploited by unauthenticated attackers to modify plugin settings either through direct requests or by manipulating authenticated users via cross-site request forgery attacks. Both attack vectors posed a risk to the plugin's configuration integrity.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.