Skip to content
No results
Menu
Web Hosting and IT Consultancy ServicesWeb Hosting and IT Consultancy Services
  • About Us
  • Blog
  • Payment Option
  • Support
  • We are hiring
Sign Up
  • Home
  • Security
  • Release
Web Hosting and IT Consultancy ServicesWeb Hosting and IT Consultancy Services

Change wp-admin Login Unauthenticated Arbitrary Settings Update Vulnerability (CVE-2022-1589) — High Severity

  • Alex JosephAlex Joseph
  • January 14, 2026
  • Security

Understanding the Threat

The Change wp-admin Login WordPress plugin, a tool designed to enhance security by allowing users to modify their WordPress admin login URL, was found to have a significant security flaw. This vulnerability, identified as CVE-2022-1589, allowed unauthorized individuals to alter the plugin’s settings without needing to log in. This could lead to attackers changing critical settings, potentially impacting your website’s security and accessibility. The issue stemmed from a lack of proper authorization checks and missing Cross-Site Request Forgery (CSRF) protection when updating the plugin’s configuration.

CVE Details

  • Product: Change wp-admin Login WordPress plugin
  • Published Date: May 30, 2022
  • Severity: High (CVSS: 7.5)
  • Status: Analyzed

Affected Products

This vulnerability affects the Change wp-admin Login WordPress plugin. Specifically, any versions of the plugin prior to 1.1.0 are at risk.

Current Status

The vulnerability for CVE-2022-1589 has been thoroughly analyzed. This means the details of the flaw are well-understood and documented, allowing developers to create and distribute fixes.

Severity Level

Rated as High severity with a CVSS score of 7.5, this vulnerability indicates a serious risk. A High severity rating means that the flaw could be exploited relatively easily by an attacker and could lead to significant impact on the affected system. In this case, unauthorized changes to login settings could severely compromise a WordPress site’s administrative control.

Possible Solutions

To protect your WordPress website from this critical vulnerability, it is essential to update your Change wp-admin Login plugin immediately. The developers have released a fix in version 1.1.0. If you are running an older version, please update to 1.1.0 or newer as soon as possible. Regular updates are crucial for maintaining the security of your WordPress installations.

References

https://wpscan.com/vulnerability/257f9e14-4f43-4852-8384-80c15d087633
https://wpscan.com/vulnerability/257f9e14-4f43-4852-8384-80c15d087633

Tags
# Change Wp Admin Login# CSRF# Plugin Vulnerability# WordPress# WordPress Security
Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.

Previous Post Change WP Admin Login Plugin Information Disclosure Vulnerability (CVE-2023-3604) — High Severity
Next Post vSlider Multi Image Slider for WordPress Cross-Site Scripting Vulnerability (CVE-2023-25797) — Medium Severity

Recent Posts

  • n8n Credential Authorization Bypass Vulnerability (CVE-2026-72774) — Medium Severity
  • n8n Account Takeover Vulnerability (CVE-2026-72772) — High Severity
  • n8n Prototype Pollution Vulnerability (CVE-2026-72769) — High Severity
  • n8n Remote Code Execution Vulnerability (CVE-2026-72767) — High Severity
  • n8n Module Cache Poisoning Vulnerability (CVE-2026-72764) — HIGH Severity

Related Posts

n8n Credential Authorization Bypass Vulnerability (CVE-2026-72774) — Medium Severity

  • Alex Joseph
  • September 19, 2026

n8n Account Takeover Vulnerability (CVE-2026-72772) — High Severity

  • Alex Joseph
  • September 18, 2026

n8n Prototype Pollution Vulnerability (CVE-2026-72769) — High Severity

  • Alex Joseph
  • September 18, 2026

Servers

  • Self Managed Dedicated Server
  • Managed Dedicated Server
  • Low Cost Dedicated Server
  • Gaming Dedicated Server
  • Dedicated server for Siberian CMS
  • Shoutcast Dedicated Server
  • Flussonic Dedicated Server

Servers Locations

  • Dedicated Servers in India
  • Dedicated Servers in China
  • Dedicated Servers in Russia
  • Dedicated Servers in Canada
  • Dedicated Servers in UK
  • Dedicated Servers in Turkey
  • Dedicated Servers in Japan

Hosting

  • Web Hosting
  • Premium cPanel Hosting
  • Reseller Hosting
  • Shared Hosting
  • Shoutcast Hosting
  • Online Radio Hosting

Solutions

  • Software Installations
  • Hire an Expert
  • Server Monitoring
  • Server Administrators
  • Hosting Support
  • cPanel Management

The Ucartz Online Pvt. Ltd. incorporated under the Ministry of Corporate Affairs, India [CIN: U72200KL2017PTC048470] and the GST Identification Number: 32AACCU0519P1ZA. By using this site, you signify that you agree to be bound by Ucartz TOS.