CVE · Medium

CVE-2019-15820 — Login or Logout Menu Item [login-or-logout-menu-item] < 1.2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-15820 Login or Logout Menu Item [login-or-logout-menu-item] < 1.2.0 URL Redirection to Untrusted Site ('Open Redirect') Medium 6.1 < 1.2.0 1.2.0 2019-08-07

CVE-2019-15820

The login-or-logout-menu-item plugin for WordPress versions before 1.2.0 lacks proper authentication checks when saving settings through the lolmi_save_settings function, allowing unauthorized users to modify plugin configuration without valid credentials.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.