DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token
high
The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.3. The vulnerability exists because `dologin\s::rrand()` seeds the Mersenne Twister with `mt_srand((double) microtime() * 1000000)` — discarding the integer-seconds compon...
- CVSS:
- 8.8
- Affected:
- up to 4.3
- Fixed in:
- 4.4
- Disclosed:
- Jul 7, 2026
CVE-2026-14495 on NVD →
DoLogin Security [dologin] < 3.8
unknown
[en] Missing Authorization vulnerability in WPDO DoLogin Security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DoLogin Security: from n/a through 3.7.1.
- Affected:
- up to 3.8
- Fixed in:
- 3.8
- Disclosed:
- Jan 2, 2025
CVE-2023-46608 on NVD →
DoLogin Security <= 3.7.1 - Missing Authorization via REST Endpoints
medium
The DoLogin Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple REST functions in versions up to, and including, 3.7.1. This makes it possible for unauthenticated attackers to send test SMS messages to arbitrary phone numbers, bypass brute force...
- CVSS:
- 6.5
- Affected:
- up to 3.7.1
- Fixed in:
- 3.8
- Disclosed:
- Oct 24, 2023
CVE-2023-46608 on NVD →
DoLogin Security [dologin] < 3.7.1
unknown
[en] The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users.
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.1
- Disclosed:
- Oct 16, 2023
CVE-2023-4800 on NVD →
DoLogin Security [dologin] < 3.7
unknown
[en] The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Sep 25, 2023
CVE-2023-4549 on NVD →
DoLogin Security [dologin] < 3.7
unknown
[en] The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Sep 25, 2023
CVE-2023-4631 on NVD →
DoLogin Security <= 3.7 - Missing Authorization on Dashboard Widget
medium
The DoLogin Security plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dashboard widget in versions up to, and including, 3.7. This makes it possible for authenticated attackers to view the login attempts log.
- CVSS:
- 4.3
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.1
- Disclosed:
- Sep 14, 2023
CVE-2023-4800 on NVD →
DoLogin Security [dologin] < 3.7.1
unknown
The DoLogin Security plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dashboard widget in versions up to, and including, 3.7. This makes it possible for authenticated attackers to view the login attempts log.
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.1
- Disclosed:
- Sep 14, 2023
DoLogin Security <= 3.6 - Unauthenticated Stored Cross-Site Scripting
high
The DoLogin Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, and including, 3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wil...
- CVSS:
- 7.2
- Affected:
- up to 3.6
- Fixed in:
- 3.7
- Disclosed:
- Aug 28, 2023
CVE-2023-4549 on NVD →
DoLogin Security <= 3.6 - IP Address Spoofing
medium
The DoLogin Security plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 3.6. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a di...
- CVSS:
- 5.3
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Aug 21, 2023
CVE-2023-4631 on NVD →
DoLogin Security [dologin] < 3.7
unknown
The DoLogin Security plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 3.6. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a di...
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Aug 21, 2023
DoLogin Security [dologin] < 3.7
unknown
Update the WordPress DoLogin Security plugin to the latest available version (at least 3.7).
WordFence discovered and reported this Bypass Vulnerability vulnerability in WordPress DoLogin Security Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability...
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Aug 21, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database