Loginizer [loginizer] < 1.9.3
unknown
[en] The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existi...
- Affected:
- up to 1.9.3
- Fixed in:
- 1.9.3
- Disclosed:
- Nov 5, 2024
CVE-2024-10097 on NVD →
Loginizer Security and Loginizer <= 1.9.2 - Authentication Bypass via WordPress.com OAuth provider
high
The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing us...
- CVSS:
- 8.1
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.3
- Disclosed:
- Nov 4, 2024
CVE-2024-10097 on NVD →
Loginizer [loginizer] < 1.7.9
unknown
[en] The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 1.7.9
- Fixed in:
- 1.7.9
- Disclosed:
- May 30, 2023
CVE-2023-2296 on NVD →
Loginizer [loginizer] < 1.7.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- May 22, 2023
CVE-2022-45079 on NVD →
Loginizer <= 1.7.8 - Reflected Cross-Site Scripting via 'limit_session[count]'
medium
The Loginizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘limit_session[count]’ parameter in versions up to, and including, 1.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.1
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.9
- Disclosed:
- May 2, 2023
CVE-2023-2296 on NVD →
Loginizer [loginizer] < 1.7.6
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- Apr 24, 2023
CVE-2022-45084 on NVD →
Loginizer <= 1.7.5 - Cross-Site Request Forgery
medium
The Loginizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.5. This is due to missing or incorrect nonce validation on the loginizer_backuply_promo() function. This makes it possible for unauthenticated attackers to install the backuply plugin via a forged reques...
- CVSS:
- 4.3
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- Dec 5, 2022
CVE-2022-45079 on NVD →
Loginizer <= 1.7.5 - Reflected Cross-Site Scripting via 'name'
medium
The Loginizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘name’ parameter in versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...
- CVSS:
- 6.1
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.6
- Disclosed:
- May 12, 2022
CVE-2022-45084 on NVD →
Loginizer <= 1.6.3 - SQL Injection
critical
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
- CVSS:
- 9.8
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Oct 21, 2020
CVE-2020-27615 on NVD →
Loginizer [loginizer] < 1.6.4
unknown
[en] The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Oct 21, 2020
CVE-2020-27615 on NVD →
Loginizer [loginizer] < 1.6.4
unknown
Unauthenticated SQL Injection (SQLi) vulnerability found by Slavco Mihajloski (mslavco) in WordPress Loginizer plugin (versions <= 1.6.3).
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Oct 21, 2020
Loginizer 1.3.8-1.3.9 - Unauthenticated Stored Cross-Site Scripting
medium
init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.
- CVSS:
- 6.1
- Affected:
- 1.3.8 – 1.3.9
- Fixed in:
- 1.4.0
- Disclosed:
- May 22, 2018
CVE-2018-11366 on NVD →
Loginizer [loginizer] >= 1.3.8 - <= 1.3.9
unknown
[en] init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.
- Affected:
- 1.3.8 – 1.3.9
- Fixed in:
- 1.3.9
- Disclosed:
- May 22, 2018
CVE-2018-11366 on NVD →
Loginizer <= 1.3.5 - Blind SQL Injection
critical
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
- CVSS:
- 9.8
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Aug 8, 2017
CVE-2017-12650 on NVD →
Loginizer <= 1.3.5 - Cross-Site Request Forgery
high
Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.
- CVSS:
- 8.8
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Aug 8, 2017
CVE-2017-12651 on NVD →
Loginizer [loginizer] < 1.3.6
unknown
[en] SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Aug 7, 2017
CVE-2017-12650 on NVD →
Loginizer [loginizer] < 1.3.6
unknown
[en] Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Aug 7, 2017
CVE-2017-12651 on NVD →
Loginizer [loginizer] < 1.7.6
unknown
Update the WordPress Loginizer plugin to the latest available version (at least 1.7.6).
Yeraisci discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Loginizer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads...
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
Loginizer [loginizer] < 1.7.6
unknown
Update the WordPress Loginizer plugin to the latest available version (at least 1.7.6).
Yeraisci discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Loginizer Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current...
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database