Lock User Account <= 1.0.5 - User Lock Bypass
medium
The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5. This is due to permitting application password logins when user accounts are locked. This makes it possible for authenticated attackers, with existing application passwords, to interact with the vul...
- CVSS:
- 4.2
- Affected:
- up to 1.0.5
- Fix:
- No patched version reported
- Disclosed:
- Nov 20, 2024
CVE-2024-11197 on NVD →
Lock User Account <= 1.0.3 - Cross-Site Request Forgery to Account Lock/Unlock
medium
The Lock User Account plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the process_lock_action() function. This makes it possible for unauthenticated attackers to unlock and lock user accounts via a forged r...
- CVSS:
- 4.3
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Aug 21, 2023
CVE-2023-4307 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database