Limit Login Attempts Plus – WordPress Limit Login Attempts By Felix [limit-login-attempts-plus] <= 1.1.0 (unfixed + closed)
unknown
[en] The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For heade...
- Affected:
- up to 1.1.0
- Fix:
- No patched version reported
- Disclosed:
- Sep 19, 2024
CVE-2022-4533 on NVD →
Limit Login Attempts Plus <= 1.1.0 - IP Address Spoofing to Protection Mechanism Bypass
medium
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header wit...
- CVSS:
- 5.3
- Affected:
- up to 1.1.0
- Fix:
- No patched version reported
- Disclosed:
- Sep 18, 2024
CVE-2022-4533 on NVD →
Limit Login Attempts Plus – WordPress Limit Login Attempts By Felix [limit-login-attempts-plus] < 1.1.0 (closed)
unknown
Update the WordPress Limit Login Attempts Plus plugin to the latest available version (at least 1.1.0).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Limit Login Attempts Plus Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertis...
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.0
- Disclosed:
- Jan 30, 2023
Limit Login Attempts Plus <= 1.0.9 - Unauthenticated Stored Cross-Site Scripting
high
The Limit Login Attempts Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- CVSS:
- 7.2
- Affected:
- up to 1.0.9
- Fixed in:
- 1.1.0
- Disclosed:
- Jan 27, 2023
Limit Login Attempts Plus <= 1.0.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Limit Login Attempts Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to i...
- CVSS:
- 5.5
- Affected:
- up to 1.0.9
- Fixed in:
- 1.1.0
- Disclosed:
- Jan 27, 2023
Limit Login Attempts Plus – WordPress Limit Login Attempts By Felix [limit-login-attempts-plus] < 1.1.0 (closed)
unknown
The Limit Login Attempts Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to i...
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.0
- Disclosed:
- Jan 27, 2023
Limit Login Attempts Plus – WordPress Limit Login Attempts By Felix [limit-login-attempts-plus] < 1.1.0 (closed)
unknown
The Limit Login Attempts Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.0
- Disclosed:
- Jan 27, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database