High 8.1
2026-01-29< 2.5.4
CVE-2025-14975
Minimum safe version
2.5.4
Update to 2.5.4 or later to address 6 fixable vulnerabilities
CVE-2025-14975
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Custom Login Page Customizer Plugin <= 2.2.2 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Custom Login Page Customizer plugin <= 2.1.7 - Sensitive Information Disclosure vulnerability
WordPress Custom Login Page Customizer plugin <= 2.1.7 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability