Limit Login Attempts <= 1.7.1 - Authenticated(Subscriber+) Stored Cross-Site Scripting
medium
The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping when displaying usernames on the log page. This makes it possible for authenticated attackers with subscriber-level permissions or...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Apr 10, 2023
CVE-2023-1861 on NVD →
Limit Login Attempts <= 1.7.1 - Unauthenticated Stored Cross-Site Scripting
high
The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that w...
- CVSS:
- 7.2
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Apr 6, 2023
CVE-2023-1912 on NVD →
Limit Login Attempts <= 1.7.0 - Brute Force Bypass
critical
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
- CVSS:
- 9.8
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.1
- Disclosed:
- Jun 1, 2012
CVE-2012-10001 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database