CVE-2018-11366
The Loginizer plugin versions 1.3.8 through 1.3.9 contain a stored cross-site scripting vulnerability in the logging functionality, which captures the REQUEST_URI variable and stores it in the database without sanitizing the input. When this stored data is displayed on the Brute Force Settings page, it renders without proper encoding, allowing an unauthenticated attacker to inject malicious JavaScript that executes when administrators view the logs. This flaw could enable an attacker to fully compromise a WordPress installation.
Based on public CVE data (MITRE/NVD).