Login Widget With Shortcode <= 6.1.2 - Open Redirect
medium
The Login Widget With Shortcode plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.1.2. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successf...
- CVSS:
- 6.1
- Affected:
- up to 6.1.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 5, 2024
CVE-2024-54255 on NVD →
Login Widget With Shortcode < 3.2.1 - Cross-Site Scripting
high
Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before 3.2.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the custom_style_afo parameter on the login_...
- CVSS:
- 7.1
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.1
- Disclosed:
- Sep 17, 2014
CVE-2014-6312 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database