What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative Studio Easy Login Styler – White Label Admin Login Page for WordPress allows Stored XSS.This issue affects Easy Login Styler – White Label Admin Login Page for WordPress: from n/a through 1.0.6.
Explanation of Vulnerability in Simple Terms
02Summary
Easy Login Styler versions up to 1.0.6 contain a stored cross-site scripting (XSS) vulnerability in the admin login page customization settings. An authenticated admin with high privileges can inject malicious scripts that execute in the browsers of other users viewing the login page. The vulnerability requires user interaction and affects the integrity and confidentiality of the site.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in visitors' browsers when they view the customized login page.
Potential impact on your site
04Site Impact
Malicious admins can steal login credentials or session tokens from users visiting your login page.
Conditions required to exploit
05Prerequisites
Admin-level access to the WordPress site and user interaction (victim must visit the login page).
Key dates
06Disclosure timeline
April 7, 2024
CVE published
April 28, 2026
Record updated