Extension WordPress
Vulnérabilités Limit Login Attempts (Spam Protection)
Cette page rassemble les failles publiées pour Limit Login Attempts (Spam Protection), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Limit Login Attempts (Spam Protection)
5 fiches
Limit Login Attempts <= 5.5 – Unauthenticated SQL Injeciton
The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-5.5
5.6
05/12/2024
Limit Login Attempts (Spam Protection) <= 5.3 – IP Address Spoofing to Protection Mechanism Bypass
The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due to insufficient restrictions on where the IP Address information is being retrieved for…
*-5.3
5.4
07/10/2024
Limit Login Attempts (Spam Protection) <= 4.9.1 – Unauthenticated SQL Injection
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections
*-4.9.1
5.1
02/03/2022
Limit Login Attempts (Spam Protection) <= 2.8 – Missing Authorization to Arbitrary Plugin Installation/Activation
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection – Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate…
[*, 2.9)
2.9
22/04/2021
Limit Login Attempts (Spam Protection) <= 2.9 – Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes…
*-2.9
3.1
22/04/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.