Extension WordPress
Vulnérabilités Loginizer
Cette page rassemble les failles publiées pour Loginizer, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Loginizer
8 fiches
Loginizer Security and Loginizer <= 1.9.2 – Authentication Bypass via WordPress.com OAuth provider
The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This…
*-1.9.2
1.9.3
04/11/2024
Loginizer <= 1.7.8 – Reflected Cross-Site Scripting via 'limit_session[count]'
The Loginizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘limit_session[count]’ parameter in versions up to, and including, 1.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-1.7.8
1.7.9
02/05/2023
Loginizer <= 1.7.5 – Cross-Site Request Forgery
The Loginizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.5. This is due to missing or incorrect nonce validation on the loginizer_backuply_promo() function. This makes it possible for unauthenticated attackers…
[*, 1.7.6)
1.7.6
05/12/2022
Loginizer <= 1.7.5 – Reflected Cross-Site Scripting via 'name'
The Loginizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘name’ parameter in versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-1.7.5
1.7.6
12/05/2022
Loginizer <= 1.6.3 – SQL Injection
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
[*, 1.6.4)
1.6.4
21/10/2020
Loginizer 1.3.8-1.3.9 – Unauthenticated Stored Cross-Site Scripting
init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.
1.3.8-1.3.9
1.4.0
22/05/2018
Loginizer <= 1.3.5 – Cross-Site Request Forgery
Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.
[*, 1.3.6)
1.3.6
08/08/2017
Loginizer <= 1.3.5 – Blind SQL Injection
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
[*, 1.3.6)
1.3.6
08/08/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.