plugin

Limit Login Attempts Reloaded Vulnerabilities

10 known security issues reported for the Limit Login Attempts Reloaded WordPress plugin. Most recent disclosed Jan 11, 2024.

1 high 3 medium

Running Limit Login Attempts Reloaded on your site? Check whether your installed version is affected.

Scan your site free

Limit Login Attempts Reloaded &#8211; Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.25.27

unknown

[en] The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...

Affected:
up to 2.25.27
Fixed in:
2.25.27
Disclosed:
Jan 11, 2024

CVE-2023-6934 on NVD →

Limit Login Attempts Reloaded <= 2.25.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with...

CVSS:
6.4
Affected:
up to 2.25.26
Fixed in:
2.25.27
Disclosed:
Dec 20, 2023

CVE-2023-6934 on NVD →

Limit Login Attempts Reloaded &#8211; Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.25.26

unknown

[en] The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.

Affected:
up to 2.25.26
Fixed in:
2.25.26
Disclosed:
Nov 27, 2023

CVE-2023-5525 on NVD →

Limit Login Attempts Reloaded <= 2.25.25 - Missing Authorization

medium

The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the toggle_auto_update() function hooked via AJAX in all versions up to, and including, 2.25.25. This makes it possible for authenticated attackers, with access to a valid nonce...

CVSS:
4.3
Affected:
up to 2.25.25
Fixed in:
2.25.26
Disclosed:
Nov 6, 2023

CVE-2023-5525 on NVD →

Limit Login Attempts Reloaded &#8211; Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.17.4

unknown

[en] The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser....

Affected:
up to 2.17.4
Fixed in:
2.17.4
Disclosed:
Dec 21, 2020

CVE-2020-35589 on NVD →

Limit Login Attempts Reloaded &#8211; Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.17.4

unknown

[en] LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limi...

Affected:
up to 2.17.4
Fixed in:
2.17.4
Disclosed:
Dec 21, 2020

CVE-2020-35590 on NVD →

Limit Login Attempts Reloaded &#8211; Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.16.0

unknown

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability found by n4nj0 in WordPress Limit Login Attempts Reloaded plugin (versions <= 2.15.2).

Affected:
up to 2.16.0
Fixed in:
2.16.0
Disclosed:
Dec 21, 2020

Limit Login Attempts Reloaded &#8211; Login Security, Brute Force Protection, Firewall [limit-login-attempts-reloaded] < 2.17.4

unknown

Login Rate Limiting Bypass vulnerability found by n4nj0 in WordPress Limit Login Attempts Reloaded plugin (versions <= 2.17.3).

Affected:
up to 2.17.4
Fixed in:
2.17.4
Disclosed:
Dec 21, 2020

Limit Login Attempts Reloaded <= 2.17.3 - Login Rate Limiting Bypass

high

LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited t...

CVSS:
7.3
Affected:
up to 2.17.3
Fixed in:
2.17.4
Disclosed:
Dec 14, 2020

CVE-2020-35590 on NVD →

Limit Login Attempts Reloaded <= 2.15.2 - Reflected Cross-Site Scripting

medium

The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The...

CVSS:
6.1
Affected:
up to 2.15.2
Fixed in:
2.17.4
Disclosed:
Dec 14, 2020

CVE-2020-35589 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database