Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown
CVE-2023-1912
Disclosure Date: April 06, 2023 (last updated October 08, 2023)
The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the plugin's settings page. This only works when the plugin prioritizes use of the X-FORWARDED-FOR header, which can be configured in its settings.
0
Attacker Value
Unknown
CVE-2022-4303
Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based restrictions on login forms.
0
Attacker Value
Unknown
CVE-2022-1029
Disclosure Date: June 27, 2022 (last updated October 07, 2023)
The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-0787
Disclosure Date: March 28, 2022 (last updated October 07, 2023)
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections
0
Attacker Value
Unknown
CVE-2021-24657
Disclosure Date: September 20, 2021 (last updated November 28, 2024)
The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2021-24194
Disclosure Date: May 14, 2021 (last updated November 28, 2024)
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
0
Attacker Value
Unknown
CVE-2012-10001
Disclosure Date: January 06, 2021 (last updated February 22, 2025)
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
0
Attacker Value
Unknown
CVE-2020-35590
Disclosure Date: December 21, 2020 (last updated February 22, 2025)
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited to perform a brute force attack, because the client IP header accepts any arbitrary string. When randomizing the header input, the login count does not ever reach the maximum allowed retries.
0
Attacker Value
Unknown
CVE-2020-35589
Disclosure Date: December 21, 2020 (last updated February 22, 2025)
The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims.
0
Attacker Value
Unknown
CVE-2015-9335
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
0