The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-05-02T07:04:50.246Z
Updated: 2024-08-02T06:05:26.603Z
Reserved: 2023-04-05T07:37:34.049Z
Link: CVE-2023-1861
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-02T08:15:10.517
Modified: 2023-11-07T04:05:14.130
Link: CVE-2023-1861
Redhat
No data.