Cross-Site Request Forgery Vulnerability in WP Custom Admin Login Page Logo by WordPress
CVE-2025-12132
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 November 2025
What is CVE-2025-12132?
The WP Custom Admin Login Page Logo plugin for WordPress is susceptible to a Cross-Site Request Forgery. This vulnerability arises from inadequate nonce validation within the wpclpl_save function, enabling unauthorized individuals to alter the plugin’s settings. An attacker can exploit this flaw by tricking an administrator into executing a deceptive request, potentially compromising the site’s configuration.
Affected Version(s)
WP Custom Admin Login Page Logo * <= 1.4.8.4