LoginWP < 3.0.0.5 - Reflected Cross-Site Scripting via rul_login_url, rul_logout_url Parameter
medium
The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login_url and rul_logout_url parameter before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 3.0.0.5
- Fixed in:
- 3.0.0.5
- Disclosed:
- Nov 8, 2021
CVE-2021-24939 on NVD →
LoginWP <= 2.9.1 - Multiple Cross-Site Request Forgery vulnerabilities
high
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
- CVSS:
- 8.8
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Feb 23, 2019
CVE-2019-15115 on NVD →
LoginWP < 2.9.1 - Cross-Site Scripting
medium
The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.
- CVSS:
- 6.1
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Aug 11, 2016
CVE-2016-10925 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database