PT-2022-13440 · WordPress · Limit Login Attempts
Cydave
·
Published
2022-03-28
·
Updated
2022-04-04
·
CVE-2022-0787
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Limit Login Attempts (Spam Protection) WordPress plugin versions prior to 5.1
Description
The issue concerns the Limit Login Attempts (Spam Protection) WordPress plugin, where certain parameters are not properly sanitized and escaped before being used in SQL statements via AJAX actions. This can lead to SQL injections, and these AJAX actions are available to unauthenticated users.
Recommendations
For versions prior to 5.1, update to version 5.1 or later to resolve the issue.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Limit Login Attempts