CVE · Medium

CVE-2018-11366 — Loginizer [loginizer] >= 1.3.8 - <= 1.3.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-11366 Loginizer [loginizer] >= 1.3.8 - <= 1.3.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 1.3.8–1.4.0 1.4.0 2018-05-22

CVE-2018-11366

The Loginizer plugin versions 1.3.8 through 1.3.9 contain a stored cross-site scripting vulnerability in the logging functionality, which captures the REQUEST_URI variable and stores it in the database without sanitizing the input. When this stored data is displayed on the Brute Force Settings page, it renders without proper encoding, allowing an unauthenticated attacker to inject malicious JavaScript that executes when administrators view the logs. This flaw could enable an attacker to fully compromise a WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.