plugin

Login Block Ips Vulnerabilities

2 known security issues reported for the Login Block Ips WordPress plugin. Most recent disclosed Sep 5, 2022.

1 high 1 medium

Running Login Block Ips on your site? Check whether your installed version is affected.

Scan your site free

Login Block IPs <= 1.0.0 - Cross-Site Request Forgery to Plugin Settings Update

high

The Login Block IPs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation in the admin/partials/login-block-ips-admin-display.php file. This makes it possible for unauthenticated attackers to update the plugin's set...

CVSS:
8.8
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
Sep 5, 2022

CVE-2022-3098 on NVD →

Login Block IPs <= 1.0.0 - IP Spoofing to Protection Mechanism Bypass

medium

The Login Block IPs plugin for WordPress is vulnerable to IP Address Spoofing in versions up to and including 1.0.0. This is due to insufficient restrictions on where the IP Address information is being retrieved in the check_is_login_page() function . Attackers can supply the HTTP_CLIENT_IP header with with a differen...

CVSS:
5.3
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Sep 5, 2022

CVE-2022-1579 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database