plugin

Guardgiant Vulnerabilities

4 known security issues reported for the Guardgiant WordPress plugin. Most recent disclosed Nov 23, 2024.

2 medium

Running Guardgiant on your site? Check whether your installed version is affected.

Scan your site free

WordPress Brute Force Protection &#8211; Stop Brute Force Attacks [guardgiant] <= 2.2.6 (unfixed + closed)

unknown

[en] The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.6. This makes it possible for unauthenticated att...

Affected:
up to 2.2.6
Fix:
No patched version reported
Disclosed:
Nov 23, 2024

CVE-2024-10869 on NVD →

GuardGiant Brute Force Protection <= 2.2.6 - Reflected Cross-Site Scripting

medium

The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.6. This makes it possible for unauthenticated attacker...

CVSS:
6.1
Affected:
up to 2.2.6
Fix:
No patched version reported
Disclosed:
Nov 22, 2024

CVE-2024-10869 on NVD →

WordPress Brute Force Protection &#8211; Stop Brute Force Attacks [guardgiant] < 2.2.6 (closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute Force Protection WordPress Brute Force Protection – Stop Brute Force Attacks.This issue affects WordPress Brute Force Protection – Stop Brute Force Attacks: from n/a through 2.2.5.

Affected:
up to 2.2.6
Fixed in:
2.2.6
Disclosed:
Dec 19, 2023

CVE-2023-48764 on NVD →

WordPress Brute Force Protection – Stop Brute Force Attacks <= 2.2.5 - Authenticated (Administrator+) SQL Injection via orderby

medium

The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 2.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...

CVSS:
6.6
Affected:
up to 2.2.5
Fixed in:
2.2.6
Disclosed:
Nov 28, 2023

CVE-2023-48764 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database