plugin

Miniorange Limit Login Attempts Vulnerabilities

2 known security issues reported for the Miniorange Limit Login Attempts WordPress plugin. Most recent disclosed Jun 6, 2022.

2 medium

Running Miniorange Limit Login Attempts on your site? Check whether your installed version is affected.

Scan your site free

MiniOrange Limit Login Attempts <= 4.0.72 - Administrator+ Cross-Site Scripting

medium

The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

CVSS:
4.8
Affected:
up to 4.0.71
Fixed in:
4.0.72
Disclosed:
Jun 6, 2022

CVE-2022-1029 on NVD →

Limit Login Attempts <= 4.0.4 - Stored Cross-Site Scripting

medium

The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.

CVSS:
6.1
Affected:
up to 4.0.50
Fixed in:
4.0.50
Disclosed:
Aug 23, 2021

CVE-2021-24657 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database