CVE Database /
CVE-2025-58595
CVE · Medium
CVE-2025-58595 — All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 2.0.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-58595
|
All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 2.0.9 |
Authentication Bypass by Spoofing |
Medium
5.3
|
< 2.0.9
|
2.0.9 |
2025-10-09 |
—
|
CVE-2025-58595
The All In One Login plugin, version 2.0.8, is susceptible to IP Address Spoofing because it inadequately validates IP addresses and relies primarily on user-supplied HTTP headers. This vulnerability allows unauthorized users to potentially circumvent the login security measures.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings