S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jul 22, 2025

CVE-2025-49029 Scanner

CVE-2025-49029 Scanner - Code Injection vulnerability in WordPress Custom Login And Signup Widget Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-49029
9.1
CVSScritical
Exploitable remotely over the internet · requires high privileges.

Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And Signup Widget: from n/a through <= 1.0.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
Custom Login And Signup Widgetby bitto.kazi
0
Updated Sep 9, 2026View on NVD →
Detail

The WordPress Custom Login And Signup Widget Plugin is widely used by website administrators to facilitate custom user login and signup functionalities. This plugin is predominantly used by WordPress site owners aiming to enhance and customize the default WordPress login experience. It's a popular choice for those who wish to provide a unique user registration and login interface on their site. Developers and webmasters leverage this plugin to integrate seamless login capabilities without extensive coding. Being a part of the widespread WordPress ecosystem, this plugin is installed by users looking to simplify login and sign-up processes. Thus, keeping the plugin secure is essential, given its prominent usage in managing user authentication tasks.

The vulnerability in question is a Code Injection vulnerability affecting versions up to and including 1.0 of the plugin. This issue allows an authenticated attacker to execute arbitrary code on the server where the plugin is installed. Such vulnerabilities are critical as they can provide a gateway for malicious actors to take control over the website's operations. The vulnerability was identified in the plugin's handling of user input within the settings page. Attackers could exploit this flaw using specially crafted inputs that allow the execution of unauthorized code. Consequently, this poses a significant threat to the integrity and security of the affected website.

Technically, the vulnerability manifests in the plugin's options page, specifically with the vulnerable 'text' parameter. By sending a POST request to the specified endpoint with crafted PHP code, an attacker can insert code into the WordPress environment. The code injection allows for the execution of arbitrary system commands via the vulnerable input area. This oversight in validating and sanitizing user-provided data leads to the potential for unauthorized command execution. As a result, affected systems can face unauthorized data manipulations and disruptions. The exploit depends on injecting PHP code where inadequate input sanitization permits its execution.

When this vulnerability is exploited by a malicious actor, the outcomes could be severe, potentially resulting in system compromise and loss of data integrity. Attackers can execute arbitrary system commands which might lead to unauthorized access to sensitive system resources. Moreover, the affected site can become a host for malicious activities, targeting users and other internet resources. Effective exploitation could result in the defacing of the website, loss of functionality, or complete takeover of the administrative operations. This breach could lead to data exfiltration or advanced persistent threats if not swiftly and effectively mitigated.

REFERENCES

Solution Advice
  • Update the plugin to the latest version to ensure known vulnerabilities are patched.
  • Implement stricter input validation and sanitization to prevent code injection attacks.
  • Regularly audit and monitor website security permissions and logs for suspicious activities.
  • Restrict plugin access to only those users who absolutely need it.
  • Engage in routine security reviews to identify and resolve potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-49029 Scanner - Code Injection vulnerability in WordPress Custom Login And Signup Widget Plugin | S4E