Skip to content

Known CVE

WordPress Customize Login Image <3.5.3 - Cross-Site Scripting

WordPress Customize Login Image plugin prior to 3.5.3 contains a cross-site scripting vulnerability via the custom logo link on the Settings page. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks.

CVE-2021-33851

Medium2021CVSS 5.4CWE-79

cve2021 · wpscan · wordpress · customize-login-image · wp · authenticated · wp-plugin · xss

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website