Sloth Logo Customizer
Sloth Logo Customizer has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Sloth Logo Customizer has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2023.
All of these findings were reported by Nithissh S. The current release is tested up to WordPress 5.4.21.
CVE-2023-0603Sloth Logo Customizer <= 2.0.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Sloth Logo Customizer
Author
ammar.shahraki
Sloth Logo customizer changes the wordpress logo on the login page and enable you to change the support string and url on the blog info widget. Major features of Blog Post filter include: Support Multisite: It supports single or multisite installation of wordpress. In multisite installation site admin could allow blogs to change logo and signature or not. Simplicity: In contrast with similar plugin this plugin is very simple and easy to use. Efficiency: The plugin has a minimum processing overhead on the site. Multilingual: Supports Persian and English admin page translation.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C