Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Joseph Kanko

#51903of 53,632
4.3Total CVSS
Vulnerabilities · 1
PT-2025-38636
4.3
2025-09-20
WordPress · Custom Login/Signup Widget · CVE-2025-9887
**Name of the Vulnerable Software and Affected Versions** Custom Login And Signup Widget versions prior to 1.0 **Description** The Custom Login And Signup Widget plugin for WordPress is susceptible to Cross-Site Request Forgery due to missing or incorrect nonce validation in the `/frndzk adminclsw.php` file. This allows unauthenticated attackers to modify email and username settings through a forged request if they can trick a site administrator into performing an action. **Recommendations** Update the Custom Login And Signup Widget plugin to a version newer than 1.0.