| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-46777 | WordPress Feather Login Page Plugin <= 1.1.3 is vulnerable to Cross Site Request Forgery (CSRF) | - | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | 中危 | - | 2023-11-06 11:06:58 | Deep Dive |
| CVE-2023-40329 | WordPress Custom Admin Login Page | WPZest Plugin <= 1.2.0 is vulnerable to Cross Site Scripting (XSS) | WPZest | Custom Admin Login Page | WPZest | Medium | 5.9 | 2023-09-06 08:24:14 | Deep Dive |
| CVE-2023-3343 | User Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object Injection | wpeverest | User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | High | 8.8 | 2023-07-13 02:04:15 | Deep Dive |
| CVE-2023-3342 | User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Upload | wpeverest | User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | Critical | 9.9 | 2023-07-13 02:04:15 | Deep Dive |
| CVE-2023-2545 | WordPress Plugin Feather Login Page 安全漏洞 | featherplugins | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | High | 8.1 | 2023-05-31 02:40:21 | Deep Dive |
| CVE-2023-2547 | WordPress Plugin Feather Login Page 安全漏洞 | featherplugins | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | Medium | 5.4 | 2023-05-31 02:40:20 | Deep Dive |
| CVE-2023-2549 | WordPress Plugin Feather Login Page Feather Login Page 跨站请求伪造漏洞 | featherplugins | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | High | 8.8 | 2023-05-31 02:40:20 | Deep Dive |
| CVE-2023-33313 | WordPress WIP Custom Login Plugin <= 1.2.9 is vulnerable to Cross Site Request Forgery (CSRF) | ThemeinProgress | WIP Custom Login | Medium | 4.3 | 2023-05-28 18:25:26 | Deep Dive |
| CVE-2023-2548 | RegistrationMagic <= 5.2.0.5 - Authenticated (Admin+) Insecure Direct Object Reference to Arbitrary User Password Change | metagauss | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Medium | 6.6 | 2023-05-16 08:40:02 | Deep Dive |
| CVE-2023-2499 | RegistrationMagic <= 5.2.1.0 - Authentication Bypass | metagauss | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Critical | 9.8 | 2023-05-16 08:40:01 | Deep Dive |
| CVE-2022-46861 | WordPress Login Page Styler Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS) | Zia Imtiaz | Custom Login Page Styler for WordPress | Medium | 5.9 | 2023-05-10 09:30:24 | Deep Dive |
| CVE-2023-26012 | WordPress Custom Login Page Plugin <= 2.0 is vulnerable to Cross Site Scripting (XSS) | Denzel Chia | Phire Design | Custom Login Page | Medium | 5.9 | 2023-05-04 13:14:07 | Deep Dive |
| CVE-2022-4519 | WP User <= 7.0 - Authenticated (Administrator+) Stored Cross-Site Scripting | walkeprashant | WP User – Custom Registration Forms, Login and User Profile | Medium | 5.5 | 2022-12-15 19:19:18 | Deep Dive |
| CVE-2022-41839 | WordPress LoginPress plugin <= 1.6.2 - Broken Access Control vulnerability | WPBrigade | LoginPress | Custom Login Page Customizer (WordPress plugin) | Medium | 5.3 | 2022-11-18 21:47:53 | Deep Dive |
| CVE-2017-20098 | Admin Custom Login Plugin Persistent cross site scripting | unspecified | Admin Custom Login Plugin | Low | 3.5 | 2022-06-27 18:11:08 | Deep Dive |
| CVE-2022-0420 | RegistrationMagic < 5.0.2.2 - Admin+ SQL Injection | Unknown | RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin | 高危 | - | 2022-03-07 08:16:33 | Deep Dive |
| CVE-2022-0347 | LoginPress < 1.5.12 - Reflected Cross-Site Scripting | Unknown | LoginPress | Custom Login Page Customizer | 中危 | - | 2022-03-07 08:16:26 | Deep Dive |
| CVE-2021-25034 | WP User < 7.0 - Reflected Cross-Site Scripting | Unknown | WP User – Custom Registration Forms, Login and User Profile | 中危 | - | 2022-02-28 09:06:32 | Deep Dive |
| CVE-2021-24944 | Custom Dashboard & Login Page < 7.0 - Admin+ Stored Cross-Site Scripting | Unknown | Custom Dashboard & Login Page – AGCA | 中危 | - | 2022-02-01 12:21:33 | Deep Dive |
| CVE-2021-24862 | RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection | Unknown | RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin | 高危 | - | 2022-01-10 15:30:30 | Deep Dive |