Custom Login URL

Custom Login URL has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Custom Login URL has a vendor fix available, so running the current release closes it.

All of these findings were reported by Nabil Irawan. Custom Login URL is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Custom Login URL vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2025-58969

Custom Login URL <= 1.0.2 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv1.0.3

Custom Login URL

Greg Winiarski

Author

Greg Winiarski

3.8(18)
76/100
Last Updated
2025-09-15 (1y ago)
Active Installs
1,000+
Downloads
50,751
Requires WP
6.0+
Requires PHP
0+
Tested up to
WP 6.8.8
Created
2014-02-24 (13y ago)

Custom Login URL (CLU) is a lightweight plugin that allows to customize default WP login, registration and password reminder URLs without modifying any files, simple and swift. Why would anyone would want to use this plugin? Well, after developing some sites it turned out that site owners do not want to reveal to customers that they are using WordPress, hence the plugin that will mask original URLs. What the plugin can do: change /wp-login.php to for example /user/login/ change /wp-login.php?action=register to for example /user/register/ change /wp-login.php?action=lostpassword to for example /user/remind/ change /wp-login.php?action=logout to for example /user/logout/ you can define your own custom paths for each URL above set successfull login and logout redirect URLs In order to make the plugin work you need to have Permalinks enabled in WP Settings.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C