CVE · Medium

CVE-2025-58595 — All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 2.0.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-58595 All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 2.0.9 Authentication Bypass by Spoofing Medium 5.3 < 2.0.9 2.0.9 2025-10-09

CVE-2025-58595

The All In One Login plugin, version 2.0.8, is susceptible to IP Address Spoofing because it inadequately validates IP addresses and relies primarily on user-supplied HTTP headers. This vulnerability allows unauthorized users to potentially circumvent the login security measures.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.