WordPress Customize Login Image plugin prior to 3.5.3 contains a cross-site scripting vulnerability via the custom logo link on the Settings page. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks.
id: CVE-2021-33851
info:
name: WordPress Customize Login Image <3.5.3 - Cross-Site Scripting
au
...