CVE · Medium

CVE-2020-35589 — Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-35589 Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.17.4 2.17.4 2020-12-14

CVE-2020-35589

The limit-login-attempts-reloaded plugin versions prior to 2.17.4 contain a reflected cross-site scripting vulnerability in the wp-admin/options-general.php page within the limit-login-attempts tab parameter. An attacker can craft a malicious URL containing harmful code that, when visited by an administrator, causes the browser to execute the injected script. This type of attack typically works by tricking users into clicking links in emails or on websites that direct them to the vulnerable plugin page with the payload embedded in the URL.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.