CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Limitloginattempts 1Limit Login Attempts Reloaded Jun 17, 2026 Jan 11, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and o...Show more |
1Limitloginattempts 1Limit Login Attempts Reloaded Jun 17, 2026 Nov 27, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin. |
1Limitloginattempts 1Limit Login Attempts Reloaded Jun 17, 2026 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configur...Show more |
1Limitloginattempts 1Limit Login Attempts Reloaded Jun 17, 2026 Dec 21, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to...Show more |