Description
The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54404 | The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form. |
References
History
Tue, 03 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpdo
Wpdo dologin Security |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wpdo:dologin_security:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpdo5ea
Wpdo5ea dologin Security |
Wpdo
Wpdo dologin Security |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T07:31:05.905Z
Reserved: 2023-08-25T15:50:35.867Z
Link: CVE-2023-4549
No data.
Status : Analyzed
Published: 2023-09-25T16:15:15.377
Modified: 2026-03-03T18:50:53.590
Link: CVE-2023-4549
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD