MiniOrange Limit Login Attempts <= 4.0.72 - Administrator+ Cross-Site Scripting
medium
The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
- CVSS:
- 4.8
- Affected:
- up to 4.0.71
- Fixed in:
- 4.0.72
- Disclosed:
- Jun 6, 2022
CVE-2022-1029 on NVD →
Limit Login Attempts <= 4.0.4 - Stored Cross-Site Scripting
medium
The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.
- CVSS:
- 6.1
- Affected:
- up to 4.0.50
- Fixed in:
- 4.0.50
- Disclosed:
- Aug 23, 2021
CVE-2021-24657 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database