The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
Metrics
Affected Vendors & Products
References
History
Thu, 30 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2023-05-02T07:04:50.246Z
Updated: 2025-01-30T15:01:03.113Z
Reserved: 2023-04-05T07:37:34.049Z
Link: CVE-2023-1861

Updated: 2024-08-02T06:05:26.603Z

Status : Modified
Published: 2023-05-02T08:15:10.517
Modified: 2025-01-30T15:15:14.450
Link: CVE-2023-1861

No data.