Extension WordPress

Vulnérabilités Limit Login Attempts (Spam Protection)

Cette page rassemble les failles publiées pour Limit Login Attempts (Spam Protection), leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
1Critiques
5Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Limit Login Attempts (Spam Protection)

5 fiches

CVE-2022-4534 Moyenne · 5,3
Limit Login Attempts (Spam Protection)

Limit Login Attempts (Spam Protection) <= 5.3 – IP Address Spoofing to Protection Mechanism Bypass

The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due to insufficient restrictions on where the IP Address information is being retrieved for…

Versions affectées

*-5.3

Correctif

5.4

Publication

07/10/2024

CVE-2021-24194 Élevée · 8,8
Limit Login Attempts (Spam Protection)

Limit Login Attempts (Spam Protection) <= 2.8 – Missing Authorization to Arbitrary Plugin Installation/Activation

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection – Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate…

Versions affectées

[*, 2.9)

Correctif

2.9

Publication

22/04/2021

Vulnérabilité Élevée · 8,8
Limit Login Attempts (Spam Protection)

Limit Login Attempts (Spam Protection) <= 2.9 – Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation

The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes…

Versions affectées

*-2.9

Correctif

3.1

Publication

22/04/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités