Custom Login URL
Custom Login URL has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Custom Login URL has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nabil Irawan. Custom Login URL is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-58969Custom Login URL <= 1.0.2 - Missing Authorization
Read the full analysisVulnerability Records
Custom Login URL
Author
Greg Winiarski
Custom Login URL (CLU) is a lightweight plugin that allows to customize default WP login, registration and password reminder URLs without modifying any files, simple and swift. Why would anyone would want to use this plugin? Well, after developing some sites it turned out that site owners do not want to reveal to customers that they are using WordPress, hence the plugin that will mask original URLs. What the plugin can do: change /wp-login.php to for example /user/login/ change /wp-login.php?action=register to for example /user/register/ change /wp-login.php?action=lostpassword to for example /user/remind/ change /wp-login.php?action=logout to for example /user/logout/ you can define your own custom paths for each URL above set successfull login and logout redirect URLs In order to make the plugin work you need to have Permalinks enabled in WP Settings.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C