YITH Custom Login

YITH Custom Login has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 5.0, and the most serious one scores 6.1 out of 10. 2024 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for YITH Custom Login has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. YITH Custom Login is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
5.0/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all YITH Custom Login vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2024-8665

YITH Custom Login <= 1.7.3 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
YITH Custom Login banner
Latestv1.7.7

YITH Custom Login

YITHEMES

Author

YITHEMES

4.8(17)
96/100
Last Updated
2025-04-24 (1y ago)
Active Installs
5,000+
Downloads
232,994
Requires WP
6.4+
Requires PHP
7.4+
Tested up to
WP 6.8.8
Created
2013-05-31 (14y ago)

Install the plugin and change the default style of wordpress login. Set a pretty style to login page of your website and customize it according to your style! Full documentation is available here. Installation Once you have installed the plugin, you just need to activate the plugin in order to enable it. Configuration YITH Custom Login will add a new page under Appearance -> Login Screen, where you can configure the plugin and customize the frontend page. GDPR Disclaimer As you can see in Google FAQ: The Google Fonts API is designed to limit the collection, storage, and use of end-user data to what is needed to serve fonts efficiently. […] Google Fonts logs records of the CSS and the font file requests, and access to this data is kept secure. […] We use data from Google’s web crawler to detect which websites use Google fonts. In other words, when someone visits your website, Google will be able to access the IP address they used to access it. As a result of using Google Fonts, you implicitly accept their terms and conditions, and you must inform people visiting your site of this in accordance with the current GDPR law in Europe. Developer Are you a developer? Want to customize the templates or the style of the plugin? Read on the documentation and discover how to do that. Suggestions If you have suggestions about how to improve YITH Custom Login, you can write us so we can bundle them into YITH Custom Login. Translators Available Languages English (Default) Italian If you have created your own language pack, or have an update for an existing one, you can send gettext PO and MO file use so we can bundle it into YITH Custom Login Languages. Documentation Full documentation is available here.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C