Input validation vulnerability in DoLogin Security 3.7

The DoLogin Security plugin for WordPress is not secure if you’re using versions up to 3.6. Attackers can use a special type of header (called X-Forwarded-For) to trick the plugin into thinking they’re logging in from a different IP address than they actually are. This means that even if the plugin has blocked certain IP addresses from logging in, the attackers can still get around it.

Detected in:

DoLogin Security open vulnerable versions: >= * < 3.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.