Login Block IPs <= 1.0.0 - Cross-Site Request Forgery to Plugin Settings Update
high
The Login Block IPs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation in the admin/partials/login-block-ips-admin-display.php file. This makes it possible for unauthenticated attackers to update the plugin's set...
- CVSS:
- 8.8
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2022
CVE-2022-3098 on NVD →
Login Block IPs <= 1.0.0 - IP Spoofing to Protection Mechanism Bypass
medium
The Login Block IPs plugin for WordPress is vulnerable to IP Address Spoofing in versions up to and including 1.0.0. This is due to insufficient restrictions on where the IP Address information is being retrieved in the check_is_login_page() function . Attackers can supply the HTTP_CLIENT_IP header with with a differen...
- CVSS:
- 5.3
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2022
CVE-2022-1579 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database