CVE-2025-14975
HIGH EXPLOITEDWordPress Custom Login Page Customizer <2.5.4 - Info Disclosure
Title source: llmDescription
The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account
Scores
CVSS v3
8.1
EPSS
0.0002
EPSS Percentile
5.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
VulnCheck KEV
2026-02-04
CWE
CWE-269
Status
published
Products (1)
Unknown/Custom Login Page Customizer
2.1.1 - 2.5.4
Published
Jan 29, 2026
Tracked Since
Feb 18, 2026