Extension WordPress

Vulnérabilités All In One Login , Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more.

Cette page rassemble les failles publiées pour All In One Login , Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more., leurs plages de versions affectées et les correctifs signalés dans la base locale.

3Vulnérabilités
0Critiques
3Avec correctif
5,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de All In One Login , Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more.

3 fiches

CVE-2025-58595 Moyenne · 5,3
All In One Login , Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more.

WordPress All In One Login Plugin <= 2.0.8 – IP Sooofing to Protection Mechanism Bypass

The All In One Login , WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more. plugin for WordPress is vulnerable to IP Address Spoofing in version 2.0.8 due to…

Versions affectées

2.0.8

Correctif

2.0.9

Publication

09/10/2025

CVE-2023-3604 Moyenne · 5,3
All In One Login , Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more.

Change WP Admin Login <= 1.1.3 – Protection Mechanism Failure to Login Page Disclosure

The Change WP Admin Login plugin for WordPress is vulnerable to Protection Mechanism Failure in versions up to, and including, 1.1.3 via the 'filter_wp_login_php' function. This can allow unauthenticated attackers to find the URL of the login page…

Versions affectées

*-1.1.3

Correctif

1.1.4

Publication

27/07/2023

CVE-2022-1589 Moyenne · 5,4
All In One Login , Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more.

Change WP Admin Login <= 1.0.9 – Missing Authorization Checks

The Change WP Admin Login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also…

Versions affectées

*-1.0.9

Correctif

1.1.0

Publication

09/05/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités