CVE-2023-1861: Limit Login Attempts < 1.7.2 - Subscriber+ Stored XSS
The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1861?
The severity of CVE-2023-1861 is medium with a CVSS score of 5.4.
What is the affected software for CVE-2023-1861?
The affected software for CVE-2023-1861 is the Limit Login Attempts WordPress plugin through version 1.7.2.
What is the vulnerability description of CVE-2023-1861?
CVE-2023-1861 is a vulnerability in the Limit Login Attempts WordPress plugin that allows any authenticated users, such as subscribers, to perform Stored Cross-Site Scripting attacks.
How can this vulnerability be exploited?
This vulnerability can be exploited by authenticated users injecting malicious scripts into their username, which will be executed when displayed in the logs dashboard.
Is there a fix for CVE-2023-1861?
To fix CVE-2023-1861, it is recommended to update to the latest version of the Limit Login Attempts WordPress plugin.