PT-2023-29565 · WordPress · Dologin Security

Bartlomiej Marek

+1

·

Published

2023-09-25

·

Updated

2023-09-26

·

CVE-2023-4549

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions DoLogin Security WordPress plugin versions prior to 3.7
Description The issue arises from improper sanitization of IP addresses from the X-Forwarded-For header, allowing attackers to conduct Stored XSS attacks through the WordPress login form.
Recommendations For versions prior to 3.7, update to version 3.7 or later to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-4549

Affected Products

Dologin Security