CVE-2025-46485: Carlo La Pera Wp Customize Login Page

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Customize Login Page: from n/a through <= 1.6.5.

Affected products

Published 2025-04-24. Last modified 2026-06-17.