The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
Metrics
Affected Vendors & Products
References
History
Thu, 30 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published: 2023-05-02T07:04:50.246Z
Updated: 2025-01-30T15:01:03.113Z
Reserved: 2023-04-05T07:37:34.049Z
Link: CVE-2023-1861
Updated: 2024-08-02T06:05:26.603Z
Status : Modified
Published: 2023-05-02T08:15:10.517
Modified: 2025-01-30T15:15:14.450
Link: CVE-2023-1861
No data.