Authorization Flaw in Login Page Customizer by A WP Life
CVE-2025-49902

6.5MEDIUM

What is CVE-2025-49902?

The Login Page Customizer plugin by A WP Life is susceptible to a missing authorization vulnerability that allows unauthorized users to exploit wrongly configured access control security levels. This weakness can lead to unauthorized actions within the plugin's user interface, posing significant risks for website owners utilizing versions from n/a to 2.1.1. It is crucial for users to ensure their installations are updated and to review their security configurations to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Login Page Customizer &#8211; Customizer Login Page, Admin Page, Custom Design <= n/a

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.