Simple Custom Login Page
Simple Custom Login Page has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Simple Custom Login Page has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nguyen Duong. Simple Custom Login Page is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.6.
CVE-2026-10100Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Simple Custom Login Page
Author
George Pattichis
Simple Custom Login Page is a simple but robust plugin to customise the login screen of your WordPress website. You can change the logo, the link and the colors (background, text, links) of the login page to match your brand’s identity. Considering all the bloated plugins and resource intensive implementations floating around, this lightweight and efficient solution is a must-have for all WordPress users/developers. It is also regularly updated to be compatible with the latest versions of WordPress and PHP. Features You can change login logo image You can change login logo link You can change page background color You can change form background color You can change label text color You can change links text color Changes are also applied to the forgot-password form Changes are also applied to the notification messages
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C