CVE Database /
CVE-2025-58595
CVE · Medium
CVE-2025-58595 — All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 2.0.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-58595
|
All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 2.0.9 |
Authentication Bypass by Spoofing |
Medium
5.3
|
< 2.0.9
|
2.0.9 |
2025-10-09 |
—
|
CVE-2025-58595
The All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. plugin for WordPress is vulnerable to IP Address Spoofing in version 2.0.8 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass login protection.
Source:
Wordfence
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings