Authorization Flaw in Login Page Customizer by A WP Life
CVE-2025-49902
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 December 2025
What is CVE-2025-49902?
The Login Page Customizer plugin by A WP Life is susceptible to a missing authorization vulnerability that allows unauthorized users to exploit wrongly configured access control security levels. This weakness can lead to unauthorized actions within the plugin's user interface, posing significant risks for website owners utilizing versions from n/a to 2.1.1. It is crucial for users to ensure their installations are updated and to review their security configurations to mitigate potential threats.
Affected Version(s)
Login Page Customizer – Customizer Login Page, Admin Page, Custom Design 0 <= 2.1.1