IP Based Login <= 2.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The IP Based Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 4.4
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Sep 22, 2025
CVE-2025-58960 on NVD →
IP Based Login [ip-based-login] <= 2.4.2 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brijeshk89 IP Based Login allows Stored XSS. This issue affects IP Based Login: from n/a through 2.4.2.
- Affected:
- up to 2.4.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2025
CVE-2025-50016 on NVD →
IP Based Login <= 2.4.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The IP Based Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 4.4
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.3
- Disclosed:
- Jun 19, 2025
CVE-2025-50016 on NVD →
IP Based Login [ip-based-login] < 2.4.1
unknown
[en] The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- May 15, 2025
CVE-2024-12800 on NVD →
IP Based Login [ip-based-login] < 2.4.1
unknown
[en] The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users delete all logs via a CSRF attack
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Mar 25, 2025
CVE-2024-13118 on NVD →
IP Based Login <= 2.4.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The IP Based Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject ar...
- CVSS:
- 4.4
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.1
- Disclosed:
- Mar 6, 2025
CVE-2024-12800 on NVD →
IP Based Login <= 2.4.0 - Cross-Site Request forgery to Log Deletion
medium
The IP Based Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete logs granted they can trick a site administrator into perfor...
- CVSS:
- 4.3
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.1
- Disclosed:
- Mar 6, 2025
CVE-2024-13118 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database