CVE Database /
CVE-2020-35589
CVE · Medium
CVE-2020-35589 — Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-35589
|
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.17.4
|
2.17.4 |
2020-12-14 |
—
|
CVE-2020-35589
The limit-login-attempts-reloaded plugin versions prior to 2.17.4 contain a reflected cross-site scripting vulnerability in the wp-admin/options-general.php page within the limit-login-attempts tab parameter. An attacker can craft a malicious URL containing harmful code that, when visited by an administrator, causes the browser to execute the injected script. This type of attack typically works by tricking users into clicking links in emails or on websites that direct them to the vulnerable plugin page with the payload embedded in the URL.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings