The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-05-02T07:04:50.246Z

Updated: 2024-08-02T06:05:26.603Z

Reserved: 2023-04-05T07:37:34.049Z

Link: CVE-2023-1861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-05-02T08:15:10.517

Modified: 2023-11-07T04:05:14.130

Link: CVE-2023-1861

cve-icon Redhat

No data.