First published: Fri Dec 29 2023(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login Form.This issue affects Login Lockdown – Protect Login Form: from n/a through 2.06.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Login Lockdown – Protect Login Form | <=2.06 |
Update to 2.07 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50837 is classified as a critical SQL Injection vulnerability that can lead to unauthorized database access.
To fix CVE-2023-50837, update the Login Lockdown – Protect Login Form plugin to version 2.07 or later.
CVE-2023-50837 affects all versions of the Login Lockdown plugin up to and including version 2.06.
CVE-2023-50837 impacts WordPress installations using the Login Lockdown – Protect Login Form plugin prior to version 2.07.
If your website is running a vulnerable version of the Login Lockdown plugin, it is at risk for exploitation through SQL Injection.