Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.25.27
unknown
[en] The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...
- Affected:
- up to 2.25.27
- Fixed in:
- 2.25.27
- Disclosed:
- Jan 11, 2024
CVE-2023-6934 on NVD →
Limit Login Attempts Reloaded <= 2.25.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with...
- CVSS:
- 6.4
- Affected:
- up to 2.25.26
- Fixed in:
- 2.25.27
- Disclosed:
- Dec 20, 2023
CVE-2023-6934 on NVD →
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.25.26
unknown
[en] The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.
- Affected:
- up to 2.25.26
- Fixed in:
- 2.25.26
- Disclosed:
- Nov 27, 2023
CVE-2023-5525 on NVD →
Limit Login Attempts Reloaded <= 2.25.25 - Missing Authorization
medium
The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the toggle_auto_update() function hooked via AJAX in all versions up to, and including, 2.25.25. This makes it possible for authenticated attackers, with access to a valid nonce...
- CVSS:
- 4.3
- Affected:
- up to 2.25.25
- Fixed in:
- 2.25.26
- Disclosed:
- Nov 6, 2023
CVE-2023-5525 on NVD →
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.17.4
unknown
[en] The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser....
- Affected:
- up to 2.17.4
- Fixed in:
- 2.17.4
- Disclosed:
- Dec 21, 2020
CVE-2020-35589 on NVD →
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.17.4
unknown
[en] LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limi...
- Affected:
- up to 2.17.4
- Fixed in:
- 2.17.4
- Disclosed:
- Dec 21, 2020
CVE-2020-35590 on NVD →
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.16.0
unknown
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability found by n4nj0 in WordPress Limit Login Attempts Reloaded plugin (versions <= 2.15.2).
- Affected:
- up to 2.16.0
- Fixed in:
- 2.16.0
- Disclosed:
- Dec 21, 2020
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.17.4
unknown
Login Rate Limiting Bypass vulnerability found by n4nj0 in WordPress Limit Login Attempts Reloaded plugin (versions <= 2.17.3).
- Affected:
- up to 2.17.4
- Fixed in:
- 2.17.4
- Disclosed:
- Dec 21, 2020
Limit Login Attempts Reloaded <= 2.17.3 - Login Rate Limiting Bypass
high
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited t...
- CVSS:
- 7.3
- Affected:
- up to 2.17.3
- Fixed in:
- 2.17.4
- Disclosed:
- Dec 14, 2020
CVE-2020-35590 on NVD →
Limit Login Attempts Reloaded <= 2.15.2 - Reflected Cross-Site Scripting
medium
The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The...
- CVSS:
- 6.1
- Affected:
- up to 2.15.2
- Fixed in:
- 2.17.4
- Disclosed:
- Dec 14, 2020
CVE-2020-35589 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database