WP Total Branding – Complete branding solution for WordPress
WP Total Branding is a complete branding toolkit for WordPress. Take full control over your WordPress look and feel. Explore the features below:
Features
- Change or remove the WordPress site generator tag
- Customize the login screen: add your logo, change links, and edit the headline
- Hide the welcome screen on the WordPress dashboard
- Remove default WordPress dashboard widgets
- Add custom footer content to the dashboard (works across all sites in multisite)
- Hide specific admin menu items
- Add custom admin notices/messages
- Remove the WordPress logo from the admin bar or upload your own
- Customize the default WordPress email sender name and address
- Disable the REST API
- Change the REST API base prefix
- Add custom CSS to the login screen
- Add custom CSS to the admin dashboard
- Add custom CSS to the front-end website
- Insert global content (header or footer) across all websites
Contributing & Bug Report
Bug reports and pull requests are welcome on Github
If you like WP Total Branding, then consider checking out our other projects:
- Magic Login Pro – Easy, secure, and passwordless authentication for WordPress.
- SessionQuota Pro – Limit concurrent sessions in WordPress.
- Stream Integration Pro – Upload, sync, restore, and manage WordPress videos with Cloudflare Stream.
- Easy Text-to-Speech – Convert written content into high-quality synthesized speech for WordPress.
- Handywriter – AI-powered writing assistant for WordPress.
- PaddlePress PRO – Paddle plugin for WordPress.
- WP Accessibility Toolkit – Tools to help make your WordPress site more accessible.
- Powered Cache – Caching and optimization for WordPress to help improve PageSpeed and Core Web Vitals.
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 5.5 MEDIUM | — | ||
The WP Total Branding – Complete branding solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. | |||