CVE Database /
CVE-2023-3604
CVE · High
CVE-2023-3604 — All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 1.1.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-3604
|
All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 1.1.4 |
Observable Discrepancy |
High
7.5
|
< 1.1.4
|
1.1.4 |
2023-07-27 |
—
|
CVE-2023-3604
The Change wp-admin login plugin for WordPress contained a bypass vulnerability prior to version 1.1.4 that allowed attackers to circumvent certain security restrictions within the plugin. Muhamad Arsyad identified and disclosed this flaw, which has been addressed in version 1.1.4 and later. Users should update to version 1.1.4 or higher to eliminate this security risk.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings