plugin

Limit Attempts Vulnerabilities

8 known security issues reported for the Limit Attempts WordPress plugin. Most recent disclosed Mar 29, 2024.

1 critical 2 medium

Running Limit Attempts on your site? Check whether your installed version is affected.

Scan your site free

Limit Attempts by BestWebSoft &#8211; WordPress Anti-Bot and Security Plugin for Login and Forms [limit-attempts] < 1.3.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BestWebSoft Limit Attempts by BestWebSoft allows Reflected XSS.This issue affects Limit Attempts by BestWebSoft: from n/a through 1.2.9.

Affected:
up to 1.3.0
Fixed in:
1.3.0
Disclosed:
Mar 29, 2024

CVE-2024-30439 on NVD →

Limit Attempts by BestWebSoft <= 1.2.9 - Reflected Cross-Site Scripting

medium

The Limit Attempts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...

CVSS:
6.1
Affected:
up to 1.2.9
Fixed in:
1.3.0
Disclosed:
Mar 28, 2024

CVE-2024-30439 on NVD →

Limit Attempts by BestWebSoft &#8211; WordPress Anti-Bot and Security Plugin for Login and Forms [limit-attempts] < 1.1.1

unknown

[en] The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.

Affected:
up to 1.1.1
Fixed in:
1.1.1
Disclosed:
Aug 22, 2019

CVE-2015-9335 on NVD →

Limit Attempts by BestWebSoft &#8211; WordPress Anti-Bot and Security Plugin for Login and Forms [limit-attempts] < 1.1.8

unknown

[en] Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,...

Affected:
up to 1.1.8
Fixed in:
1.1.8
Disclosed:
May 22, 2017

CVE-2017-2171 on NVD →

Limit Attempts by BestWebSoft < 1.1.8 - Reflected Cross-Site Scripting

medium

The Limit Attempts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 1.1.8
Fixed in:
1.1.8
Disclosed:
Apr 12, 2017

Limit Attempts by BestWebSoft &#8211; WordPress Anti-Bot and Security Plugin for Login and Forms [limit-attempts] < 1.1.8

unknown

The Limit Attempts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

Affected:
up to 1.1.8
Fixed in:
1.1.8
Disclosed:
Apr 12, 2017

Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms < 1.1.1 - SQL Injection

critical

The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.

CVSS:
9.8
Affected:
up to 1.1.1
Fixed in:
1.1.1
Disclosed:
Oct 9, 2015

CVE-2015-9335 on NVD →

Limit Attempts by BestWebSoft &#8211; WordPress Anti-Bot and Security Plugin for Login and Forms [limit-attempts] < 1.1.8

unknown
Affected:
up to 1.1.8
Fixed in:
1.1.8

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database