plugin

Ldap Wp Login Integration With Active Directory Vulnerabilities

1 known security issue reported for the Ldap Wp Login Integration With Active Directory WordPress plugin. Most recent disclosed Sep 5, 2022.

1 high

Running Ldap Wp Login Integration With Active Directory on your site? Check whether your installed version is affected.

Scan your site free

Ldap WP Login / Active Directory Integration <= 3.0.1 - Missing Authorization

high

The Ldap WP Login / Active Directory Integration plugin for WordPress is vulnerable to authorization bypass and Cross-Site Request Forgery in versions up to, and including 3.0.1, due to missing nonce and capability checks on several of it's functions called via init hooks. This makes it possible for unauthenticated att...

CVSS:
7.3
Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Sep 5, 2022

CVE-2022-2987 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database