The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
History

Thu, 30 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-05-02T07:04:50.246Z

Updated: 2025-01-30T15:01:03.113Z

Reserved: 2023-04-05T07:37:34.049Z

Link: CVE-2023-1861

cve-icon Vulnrichment

Updated: 2024-08-02T06:05:26.603Z

cve-icon NVD

Status : Modified

Published: 2023-05-02T08:15:10.517

Modified: 2025-01-30T15:15:14.450

Link: CVE-2023-1861

cve-icon Redhat

No data.