Input validation vulnerability in MelaPress Login Security 1.3.0

The MelaPress Login Security plugin for WordPress has a security issue that could affect all versions up to 1.3.0. The problem is with the ‘tab’ parameter, which could allow attackers with high-level access to include and run files from remote servers. This means they could potentially run any PHP code contained in those files. This could be used to get around security measures, access confidential information, or even execute code. Keep in mind that the site must have the allow_url_include setting turned on for this to work.

Detected in:

MelaPress Login Security fixed vulnerable versions: >= * <= 1.3.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.