plugin

Lock User Account Vulnerabilities

2 known security issues reported for the Lock User Account WordPress plugin. Most recent disclosed Nov 20, 2024.

2 medium

Running Lock User Account on your site? Check whether your installed version is affected.

Scan your site free

Lock User Account <= 1.0.5 - User Lock Bypass

medium

The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5. This is due to permitting application password logins when user accounts are locked. This makes it possible for authenticated attackers, with existing application passwords, to interact with the vul...

CVSS:
4.2
Affected:
up to 1.0.5
Fix:
No patched version reported
Disclosed:
Nov 20, 2024

CVE-2024-11197 on NVD →

Lock User Account <= 1.0.3 - Cross-Site Request Forgery to Account Lock/Unlock

medium

The Lock User Account plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the process_lock_action() function. This makes it possible for unauthenticated attackers to unlock and lock user accounts via a forged r...

CVSS:
4.3
Affected:
up to 1.0.3
Fixed in:
1.0.4
Disclosed:
Aug 21, 2023

CVE-2023-4307 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database