Executive brief
The MP Customize Login Page plugin for WordPress, which allows site owners to personalize their login screens, contains a security flaw that allows unauthorized changes to its settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify the login page's appearance, including background images, logos, and messages. This could be used to deface the site's entry point or facilitate phishing attacks by changing the destination of the login logo.
Technical details
The vulnerability exists in the enter_mpclp_login_options() function due to a broken nonce validation mechanism. The code contains an inverted logic check where a successful nonce verification returns false, and it fails to provide the required action parameter to wp_verify_nonce(), rendering the security check ineffective. Additionally, the settings-update handler is hooked to 'init' without any capability checks. An attacker can exploit this by crafting a malicious request and using social engineering to induce a logged-in administrator to execute it, leading to unauthorized modification of plugin settings such as logo URLs and background configurations.
Affected products
- manuelpadillac MP Customize Login Page up to and including 1.0
Timeline
- 2026-06-24: disclosed: CVE published to the NVD dataset
References
- https://plugins.trac.wordpress.org/browser/mp-customize-login-page/tags/1.0/class.mp-customize-login-page.php
- https://plugins.trac.wordpress.org/browser/mp-customize-login-page/tags/1.0/class.mp-customize-login-page.php
- https://plugins.trac.wordpress.org/browser/mp-customize-login-page/trunk/class.mp-customize-login-page.php
- https://plugins.trac.wordpress.org/browser/mp-customize-login-page/trunk/class.mp-customize-login-page.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b9216875-8cb6-45a7-b23b-19d13f8b49dc?source=cve