plugin

Brute Force Login Protection Vulnerabilities

1 known security issue reported for the Brute Force Login Protection WordPress plugin. Most recent disclosed May 17, 2015.

1 high

Running Brute Force Login Protection on your site? Check whether your installed version is affected.

Scan your site free

Brute Force Login Protection <= 1.5.1 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module up to and including 1.5.1 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that have unknown impact via a crafted request to the brute-force-login-protection page to wp-admin/op...

CVSS:
8.8
Affected:
up to 1.5.1
Fix:
No patched version reported
Disclosed:
May 17, 2015

CVE-2014-5034 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database