CVE Database
/

CVE-2025-14975

Back to search

CVE-2025-14975

Published: Jan 29, 2026

Modified: Jan 29, 2026

PUBLISHED

Description

The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

VendorProductVersions

Unknown

Custom Login Page Customizer

affected
2.1.1 - < 2.5.4

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now