CVE-2025-50016: WordPress IP Based Login plugin <= 2.4.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brijeshk89 IP Based Login allows Stored XSS. This issue affects IP Based Login: from n/a through 2.4.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brijeshk89 IP Based Login ip-based-login allows Stored XSS.This issue affects IP Based Login: from n/a through <= 2.4.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50016?
CVE-2025-50016 is classified as a critical vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2025-50016?
To mitigate CVE-2025-50016, update the IP Based Login plugin to a version higher than 2.4.2.
What systems are affected by CVE-2025-50016?
CVE-2025-50016 affects the WordPress IP Based Login plugin versions up to and including 2.4.2.
What type of attack does CVE-2025-50016 enable?
CVE-2025-50016 enables stored cross-site scripting (XSS) attacks.
How can I identify if my site is vulnerable to CVE-2025-50016?
You can check if your site is vulnerable by confirming the version of the IP Based Login plugin is 2.4.2 or earlier.