PT-2024-17959 · WordPress · The Login Lockdown – Protect Login Form

Lucio Sá

·

Published

2024-02-20

·

Updated

2024-02-29

·

CVE-2024-1340

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Login Lockdown – Protect Login Form plugin for WordPress versions up to, and including, 2.08
Description The issue is related to a missing capability check on the generate export file function. This allows authenticated attackers with subscriber access or higher to export the plugin's settings, which include whitelisted IP addresses and a global unlock key. The global unlock key can be used by an attacker to add their IP address to the whitelist.
Recommendations For versions up to, and including, 2.08, update to a version that includes a fix for the missing capability check on the generate export file function to prevent unauthorized access to the plugin's settings. As a temporary workaround, consider restricting access to the generate export file function to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1340

Affected Products

The Login Lockdown – Protect Login Form