Input validation vulnerability in Limit Login Attempts Plus – WordPress Limit Login Attempts By Felix 1.0.9

The Limit Login Attempts Plus plugin for WordPress is vulnerable to a type of security risk called Stored Cross-Site Scripting. This vulnerability allows malicious people with administrative privileges to inject malicious code, like web scripts, on pages in the website. This malicious code will then be executed whenever anyone visits the page. This vulnerability only affects multi-site WordPress installations or installations where the “unfiltered_html” option has been disabled. This vulnerability affects all versions of Limit Login Attempts Plus up to, and including, 1.0.9.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.