Executive brief
The Super Custom Login plugin for WordPress, which allows site owners to customize their login pages, contains a security flaw in its access control settings. An unauthorized person could potentially bypass intended security levels to perform actions they should not be allowed to do. This could lead to unauthorized changes to the site's configuration or login behavior.
Technical details
The Super Custom Login plugin for WordPress (versions up to and including 1.1) is vulnerable to broken access control due to missing authorization checks (CWE-862). The vulnerability exists within the 'super-custom-login' component, where security levels for access control are incorrectly enforced. A remote, unauthenticated attacker can exploit this flaw to execute functions or modify settings that should be restricted to higher-privileged users. As of the advisory date, no official patch has been released by the vendor.
Affected products
- Obadiah Super Custom Login <= 1.1
Timeline
- 2026-01-04: other: Vulnerability reported by researcher Legion Hunter
- 2026-02-03: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD