Stored XSS Vulnerability in WP Customize Login Page by Carlo La Pera
CVE-2025-46477
5.9MEDIUM
What is CVE-2025-46477?
An issue has been identified in the WP Customize Login Page plugin created by Carlo La Pera, where improper sanitization of user input allows for a stored Cross-site Scripting (XSS) vulnerability. This flaw may permit attackers to inject malicious scripts, which can be executed on the client side when users interact with the affected web pages. This vulnerability impacts all versions from n/a up to 1.6.5, emphasizing the need for users to upgrade and implement security measures to protect their applications.
Affected Version(s)
WP Customize Login Page 0 <= 1.6.5