CVE-2026-93622: WordPress WPS Limit Login plugin <= 1.5.9.3 - Cross Site Scripting (XSS) vulnerability
Published Sep 23, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.
Affected Software
1 affected component
WordPress WPS Limit Login<=1.5.9.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPS Limit Login pluginto a version that resolves this vulnerability.Fixed in 1.5.9.4
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or plugin privileges. Exploitation requires user interaction, as indicated by the UI:R vector.
2
Which plugin versions are affected?
WPS Limit Login versions 1.5.9.3 and earlier are affected according to the available information.
3
What impact could successful exploitation have?
The reported CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. The issue is classified as cross-site scripting, so impact depends on a user interacting with attacker-supplied content.