CVE-2023-1893: Login Configurator Project Login Configurator
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.
Affected products
- Login Configurator Project Login Configurator: up to and including 2.1
Published 2023-07-17. Last modified 2026-06-17.