Authorization Flaw in Login Page Customizer by A WP Life
CVE-2025-49902
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 December 2025
What is CVE-2025-49902?
The Login Page Customizer plugin by A WP Life is susceptible to a missing authorization vulnerability that allows unauthorized users to exploit wrongly configured access control security levels. This weakness can lead to unauthorized actions within the plugin's user interface, posing significant risks for website owners utilizing versions from n/a to 2.1.1. It is crucial for users to ensure their installations are updated and to review their security configurations to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Login Page Customizer – Customizer Login Page, Admin Page, Custom Design <= n/a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved