CVE Database /
CVE-2025-14975
CVE · High
CVE-2025-14975 — Custom Login Page Customizer [login-customizer] < 2.5.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-14975
|
Custom Login Page Customizer [login-customizer] < 2.5.4 |
Improper Privilege Management |
High
8.1
|
< 2.5.4
|
2.5.4 |
2026-01-08 |
—
|
CVE-2025-14975
The Custom Login Page Customizer plugin in WordPress versions up to 2.5.3 is susceptible to privilege escalation through an account takeover attack. The vulnerability arises because the plugin fails to adequately verify a user’s identity before updating passwords. As a result, unauthorized attackers can alter any user's password, including admin accounts, potentially granting them access to those accounts.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings