CVE · High

CVE-2023-3604 — All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 1.1.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3604 All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 1.1.4 Observable Discrepancy High 7.5 < 1.1.4 1.1.4 2023-07-27

CVE-2023-3604

The Change wp-admin login plugin for WordPress contained a bypass vulnerability prior to version 1.1.4 that allowed attackers to circumvent certain security restrictions within the plugin. Muhamad Arsyad identified and disclosed this flaw, which has been addressed in version 1.1.4 and later. Users should update to version 1.1.4 or higher to eliminate this security risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.