plugin

Ldap Login For Intranet Sites Vulnerabilities

17 known security issues reported for the Ldap Login For Intranet Sites WordPress plugin. Most recent disclosed Oct 18, 2023.

3 high 3 medium 2 low

Running Ldap Login For Intranet Sites on your site? Check whether your installed version is affected.

Scan your site free

Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 3.6.95

unknown

Update the WordPress Active Directory Integration / LDAP Integration plugin to the latest available version (at least 3.6.95). WPScanTeam discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Active Directory Integration / LDAP Integration Plugin. This could allow a malicious actor to injec...

Affected:
up to 3.6.95
Fixed in:
3.6.95
Disclosed:
Oct 18, 2023

Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.1.10

unknown

[en] The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.

Affected:
up to 4.1.10
Fixed in:
4.1.10
Disclosed:
Oct 16, 2023

CVE-2023-5003 on NVD →

Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.2

unknown

[en] The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change...

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Sep 26, 2023

CVE-2023-4506 on NVD →

Active Directory Integration / LDAP Integration <= 4.1.9 - Sensitive Information Exposure

high

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.9 via a publicly accessible LDAP log buffer created when an administrator exports the logs. This makes it possible for unauthenticated attackers to visit the log...

CVSS:
7.5
Affected:
up to 4.1.9
Fixed in:
4.1.10
Disclosed:
Sep 25, 2023

CVE-2023-4506 on NVD →

Active Directory Integration / LDAP Integration <= 4.1.9 - Unauthenticated Information Disclosure

medium

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.1.9 via log files that are left over and not deleted. This makes it possible for unauthenticated attackers to extract potentially sensitive data including errors and inf...

CVSS:
5.3
Affected:
up to 4.1.9
Fixed in:
4.1.10
Disclosed:
Sep 25, 2023

CVE-2023-5003 on NVD →

Active Directory Integration / LDAP Integration <= 4.1.10 - LDAP Passback

low

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the...

CVSS:
2.2
Affected:
up to 4.1.10
Fixed in:
4.2
Disclosed:
Sep 25, 2023

CVE-2023-4506 on NVD →

Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.1.6

unknown

[en] The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for unauthenticated attackers to extract potentially sensitive information fr...

Affected:
up to 4.1.6
Fixed in:
4.1.6
Disclosed:
Jun 29, 2023

CVE-2023-3447 on NVD →

Active Directory Integration / LDAP Integration <= 4.1.5 - Authenticated (Subscriber+) LDAP Injection

high

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to ext...

CVSS:
7.6
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Jun 28, 2023

CVE-2023-3447 on NVD →

Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.1.5

unknown

[en] The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possi...

Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Jun 9, 2023

CVE-2023-2484 on NVD →

Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.1.5

unknown

[en] The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user suppli...

Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Jun 9, 2023

CVE-2023-2599 on NVD →

Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.1.1

unknown

[en] The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
May 15, 2023

CVE-2023-0812 on NVD →

Active Directory Integration / LDAP Integration <= 4.1.4 - Authenticated (Administrator+) SQL Injection

high

The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible f...

CVSS:
7.2
Affected:
up to 4.1.4
Fixed in:
4.1.5
Disclosed:
May 12, 2023

CVE-2023-2484 on NVD →

Active Directory Integration / LDAP Integration <= 4.1.4 - Cross-Site Request Forgery to SQL Injection

low

The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied pa...

CVSS:
3.1
Affected:
up to 4.1.4
Fixed in:
4.1.5
Disclosed:
May 12, 2023

CVE-2023-2599 on NVD →

Active Directory Integration / LDAP Integration <= 4.1.0 - Unauthenticated Information Disclosure

medium

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.0 via the 'test_attribute_configuration'. This can allow unauthenticated attackers to extract sensitive data including configuration settings.

CVSS:
5.3
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Apr 19, 2023

CVE-2023-0812 on NVD →

Active Directory Integration / LDAP Integration <= 3.6.94 - Reflected Cross-Site Scripting

medium

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘test_username’ parameter in versions up to, and including 3.6.94 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...

CVSS:
6.1
Affected:
up to 3.6.95
Fixed in:
3.6.95
Disclosed:
Oct 18, 2021

Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 3.6.95

unknown

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘test_username’ parameter in versions up to, and including 3.6.94 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...

Affected:
up to 3.6.95
Fixed in:
3.6.95
Disclosed:
Oct 18, 2021

Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 3.6.95

unknown

The plugin does not escape the test_username parameter before outputting it back in the settings page, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 3.6.95
Fixed in:
3.6.95

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database