Known vulnerabilities in LoginPress | wp-login Custom Login Page Customizer
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
6Reported vulnerabilities
9.8Highest CVSS score
6.2.5Latest version
200,000+Active installs
What to do now
Update LoginPress | wp-login Custom Login Page Customizer to 4.0.0 or later.
6 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2019-15872 | Critical | 2.2% | Before 1.1.4 | 1.1.4 |
September 3, 2019 |
| CVE-2022-0347 | Medium | 0.8% | Before 1.5.12 | 1.5.12 |
March 7, 2022 |
| CVE-2019-15871 | Medium | 0.9% | 1.1.13 and earlier | 1.1.14 |
September 3, 2019 |
| CVE-2025-1764 | High | 0.2% | 0 to 3.3.1 (inclusive) | 4.0.0 |
March 14, 2025 |
| WF-65fc55bb-2b86-466a-b43b-554628283f02 | Medium | — | Before 1.1.16 | 1.1.16 |
December 7, 2018 |
| CVE-2022-41839 | Medium | 0.5% | 1.6.2 and earlier | 1.6.3 |
November 18, 2022 |