CVE-2026-10100: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in pattihis Simple Custom Login Page
The Simple Custom Login Page plugin for WordPress up to version 1.0.3 is vulnerable to stored cross-site scripting (XSS) via color setting fields. This vulnerability arises from improper sanitization of input values used in CSS contexts, allowing authenticated administrators to inject arbitrary CSS into the login page. The injected CSS affects all unauthenticated visitors, potentially enabling UI redress and credential phishing attacks. The vulnerability has a medium severity with a CVSS score of 4.4. No official patch or remediation guidance is currently available.
AI Analysis
Technical Summary
CVE-2026-10100 describes a stored cross-site scripting vulnerability in the Simple Custom Login Page WordPress plugin (up to version 1.0.3). The issue stems from insufficient input sanitization of color option fields (Page Background, Form Background, Text Color, Link Color) registered via register_setting() without a sanitize_callback. These values are output into a <style> block on wp-login.php using esc_attr(), which does not properly escape characters critical in CSS contexts, such as ;, {, }, /, or *. Consequently, authenticated users with administrator privileges can inject arbitrary CSS rules into the login page, which are rendered for all unauthenticated visitors. This can facilitate UI redress and credential phishing attacks. No known exploits in the wild have been reported, and no official fix or patch is documented at this time.
Potential Impact
An authenticated attacker with administrator-level access can inject arbitrary CSS into the WordPress login page, affecting all unauthenticated visitors. This can lead to UI redress attacks and credential phishing by manipulating the login page appearance. The confidentiality and integrity impacts are low, as the vulnerability does not allow direct code execution or data theft, but it can mislead users and compromise login security.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict administrator access to trusted users only and monitor for suspicious changes to plugin settings. Avoid using the affected plugin version if possible or disable it temporarily to mitigate risk.
CVE-2026-10100: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in pattihis Simple Custom Login Page
Description
The Simple Custom Login Page plugin for WordPress up to version 1.0.3 is vulnerable to stored cross-site scripting (XSS) via color setting fields. This vulnerability arises from improper sanitization of input values used in CSS contexts, allowing authenticated administrators to inject arbitrary CSS into the login page. The injected CSS affects all unauthenticated visitors, potentially enabling UI redress and credential phishing attacks. The vulnerability has a medium severity with a CVSS score of 4.4. No official patch or remediation guidance is currently available.
CVSS v3.1
Score 4.4medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-10100 describes a stored cross-site scripting vulnerability in the Simple Custom Login Page WordPress plugin (up to version 1.0.3). The issue stems from insufficient input sanitization of color option fields (Page Background, Form Background, Text Color, Link Color) registered via register_setting() without a sanitize_callback. These values are output into a <style> block on wp-login.php using esc_attr(), which does not properly escape characters critical in CSS contexts, such as ;, {, }, /, or *. Consequently, authenticated users with administrator privileges can inject arbitrary CSS rules into the login page, which are rendered for all unauthenticated visitors. This can facilitate UI redress and credential phishing attacks. No known exploits in the wild have been reported, and no official fix or patch is documented at this time.
Potential Impact
An authenticated attacker with administrator-level access can inject arbitrary CSS into the WordPress login page, affecting all unauthenticated visitors. This can lead to UI redress attacks and credential phishing by manipulating the login page appearance. The confidentiality and integrity impacts are low, as the vulnerability does not allow direct code execution or data theft, but it can mislead users and compromise login security.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict administrator access to trusted users only and monitor for suspicious changes to plugin settings. Avoid using the affected plugin version if possible or disable it temporarily to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-05-29T15:07:45.775Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1e40ffe29bf47b506f6b94
Added to database: 06/02/2026, 02:33:35 UTC
Last enriched: 06/09/2026, 09:52:38 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.