plugin

Limit Login Attempts Vulnerabilities

3 known security issues reported for the Limit Login Attempts WordPress plugin. Most recent disclosed Apr 10, 2023.

1 critical 1 high 1 medium

Running Limit Login Attempts on your site? Check whether your installed version is affected.

Scan your site free

Limit Login Attempts <= 1.7.1 - Authenticated(Subscriber+) Stored Cross-Site Scripting

medium

The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping when displaying usernames on the log page. This makes it possible for authenticated attackers with subscriber-level permissions or...

CVSS:
6.4
Affected:
up to 1.7.1
Fixed in:
1.7.2
Disclosed:
Apr 10, 2023

CVE-2023-1861 on NVD →

Limit Login Attempts <= 1.7.1 - Unauthenticated Stored Cross-Site Scripting

high

The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that w...

CVSS:
7.2
Affected:
up to 1.7.1
Fixed in:
1.7.2
Disclosed:
Apr 6, 2023

CVE-2023-1912 on NVD →

Limit Login Attempts <= 1.7.0 - Brute Force Bypass

critical

The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.

CVSS:
9.8
Affected:
up to 1.7.0
Fixed in:
1.7.1
Disclosed:
Jun 1, 2012

CVE-2012-10001 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database