RSS   Podatności dla 'Limit login attempts'   RSS

2022-03-28
 
CVE-2022-0787

CWE-89
 

 
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

 
2021-01-06
 
CVE-2012-10001

CWE-287
 

 
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.

 


Copyright 2024, cxsecurity.com

 

Back to Top