Login Screen Manager [login-screen-manager] <= 3.5.2 (unfixed + closed)
unknown
[en] Cross-Site Request Forgery (CSRF) leading to a Stored Cross-Site Scripting (XSS) vulnerability in Nazmul Hossain Nihal Login Screen Manager plugin <= 3.5.2 versions.
- Affected:
- up to 3.5.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2023
CVE-2023-47182 on NVD →
Login Screen Manager <= 3.5.2 - Cross-Site Request Forgery
medium
The Login Screen Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.2. This is due to missing or incorrect nonce validation on the cwlsm_options_page() function. This makes it possible for unauthenticated attackers to update the plugin's settings and injec...
- CVSS:
- 6.1
- Affected:
- up to 3.5.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 31, 2023
CVE-2023-47182 on NVD →
Login Screen Manager [login-screen-manager] <= 3.5.2 (unfixed + closed)
unknown
[en] The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.5.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 31, 2023
CVE-2023-5243 on NVD →
Login Screen Manager <= 3.5.2 - Authenticated(Admin+) Stored Cross-Site Scripting
medium
The Login Screen Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 3.5.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 9, 2023
CVE-2023-5243 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database