Input validation vulnerability in Limit Login Attempts Plus – WordPress Limit Login Attempts By Felix 1.0.9

The Limit Login Attempts Plus plugin for WordPress has a security vulnerability in versions up to and including 1.4. This vulnerability makes it possible for people who are not authenticated (or logged in) to inject dangerous web scripts into pages when an administrator looks at the settings page of the plugin. This web script can then do whatever the attacker wants it to do. To fix this problem, the plugin needs to be updated to ensure that all inputs are sanitized and all outputs are escaped.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.