WordPress Brute Force Protection – Stop Brute Force Attacks [guardgiant] <= 2.2.6 (unfixed + closed)
unknown
[en] The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.6. This makes it possible for unauthenticated att...
- Affected:
- up to 2.2.6
- Fix:
- No patched version reported
- Disclosed:
- Nov 23, 2024
CVE-2024-10869 on NVD →
GuardGiant Brute Force Protection <= 2.2.6 - Reflected Cross-Site Scripting
medium
The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.6. This makes it possible for unauthenticated attacker...
- CVSS:
- 6.1
- Affected:
- up to 2.2.6
- Fix:
- No patched version reported
- Disclosed:
- Nov 22, 2024
CVE-2024-10869 on NVD →
WordPress Brute Force Protection – Stop Brute Force Attacks [guardgiant] < 2.2.6 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute Force Protection WordPress Brute Force Protection – Stop Brute Force Attacks.This issue affects WordPress Brute Force Protection – Stop Brute Force Attacks: from n/a through 2.2.5.
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
- Disclosed:
- Dec 19, 2023
CVE-2023-48764 on NVD →
WordPress Brute Force Protection – Stop Brute Force Attacks <= 2.2.5 - Authenticated (Administrator+) SQL Injection via orderby
medium
The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 2.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...
- CVSS:
- 6.6
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.6
- Disclosed:
- Nov 28, 2023
CVE-2023-48764 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database