Sloth Logo Customizer

Sloth Logo Customizer has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Sloth Logo Customizer has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2023.

All of these findings were reported by Nithissh S. The current release is tested up to WordPress 5.4.21.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Sloth Logo Customizer vulnerabilities before they are exploited.

Most severe open issueCVSS 6.1CVE-2023-0603

Sloth Logo Customizer <= 2.0.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv2.0.2

Sloth Logo Customizer

ammar.shahraki

Author

ammar.shahraki

0.0(0)
0/100
Last Updated
2020-04-02 (7y ago)
Active Installs
0+
Downloads
1,510
Requires WP
4.2.4+
Requires PHP
0+
Tested up to
WP 5.4.21
Created
2017-06-30 (9y ago)

Sloth Logo customizer changes the wordpress logo on the login page and enable you to change the support string and url on the blog info widget. Major features of Blog Post filter include: Support Multisite: It supports single or multisite installation of wordpress. In multisite installation site admin could allow blogs to change logo and signature or not. Simplicity: In contrast with similar plugin this plugin is very simple and easy to use. Efficiency: The plugin has a minimum processing overhead on the site. Multilingual: Supports Persian and English admin page translation.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C