← Back

Dologin Security

dologin_security

Vendor: Wpdo • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpdo
1Dologin Security
Jun 17, 2026
Oct 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users.
2Wpdo
Wpdo5ea
2Dologin Security
Dologin Security
Jun 17, 2026
Sep 25, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.
2Wpdo
Wpdo5ea
2Dologin Security
Dologin Security
Jun 17, 2026
Sep 25, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.