Vulnerability Description
The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-14975?
CVE-2025-14975 is a vulnerability with a CVSS score of 8.1 (HIGH). The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their...
How severe is CVE-2025-14975?
CVE-2025-14975 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14975?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.