WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Admin Custom Login

Customize Your WordPress Login Screen Amazingly - Add Own Logo, Add Social Profiles, Login Form Positions, Background Image Slide Show

3Reported vulnerabilities
8.8Highest CVSS score
3.6.7Latest version
20,000+Active installs

What to do now

Update Admin Custom Login to 3.6.5 or later. 3 of these have a fixed version available. Updating resolves them.

Plugin last updated: June 10, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-34628 High 8.8 0.7% 3.2.7 and earlier 3.2.8 August 2, 2021
WF-5f2f34e1-3b08-4e23-a29b-21e61e6a6063 High 8.8 Before 2.4.8 2.4.8 March 1, 2017
CVE-2026-2487 Medium 4.4 0.2% 0 to 3.6.4 (inclusive) 3.6.5 August 16, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.