The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24879 | The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 14 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpexperts
Wpexperts all In One Login |
|
| CPEs | cpe:2.3:a:wpexperts:all_in_one_login:*:*:*:*:-:wordpress:*:* | |
| Vendors & Products |
Change Wp-admin Login Project
Change Wp-admin Login Project change Wp-admin Login |
Wpexperts
Wpexperts all In One Login |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T00:10:03.626Z
Reserved: 2022-05-05T00:00:00
Link: CVE-2022-1589
No data.
Status : Analyzed
Published: 2022-05-30T09:15:10.157
Modified: 2026-01-14T18:58:52.957
Link: CVE-2022-1589
No data.
OpenCVE Enrichment
No data.
EUVD