Lucene search

K
wpvulndbWordfenceWPVDB-ID:7720B38F-8862-4897-8E05-8E5964F0415F
HistoryJul 28, 2021 - 12:00 a.m.

Admin Custom Login < 3.2.8 - CSRF to Stored XSS

2021-07-2800:00:00
Wordfence
wpscan.com
17

0.001 Low

EPSS

Percentile

47.3%

The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-setting/Login-form-background.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.7.

PoC

CPENameOperatorVersion
admin-custom-loginlt3.2.8

0.001 Low

EPSS

Percentile

47.3%

Related for WPVDB-ID:7720B38F-8862-4897-8E05-8E5964F0415F