Simple Custom Login Page

Simple Custom Login Page has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Simple Custom Login Page has a vendor fix available, so running the current release closes it.

All of these findings were reported by Nguyen Duong. Simple Custom Login Page is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.6.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Simple Custom Login Page vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2026-10100

Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Simple Custom Login Page banner
Latestv1.0.4

Simple Custom Login Page

George Pattichis

Author

George Pattichis

5.0(3)
100/100
Last Updated
2026-04-01 (5mo ago)
Active Installs
60+
Downloads
3,073
Requires WP
5.3.0+
Requires PHP
7.0+
Tested up to
WP 6.9.6
Created
2023-12-31 (3y ago)

Simple Custom Login Page is a simple but robust plugin to customise the login screen of your WordPress website. You can change the logo, the link and the colors (background, text, links) of the login page to match your brand’s identity. Considering all the bloated plugins and resource intensive implementations floating around, this lightweight and efficient solution is a must-have for all WordPress users/developers. It is also regularly updated to be compatible with the latest versions of WordPress and PHP. Features You can change login logo image You can change login logo link You can change page background color You can change form background color You can change label text color You can change links text color Changes are also applied to the forgot-password form Changes are also applied to the notification messages

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C