CVE Database /
CVE-2023-5525
CVE · Medium
CVE-2023-5525 — Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-5525
|
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26 |
Missing Authorization |
Medium
4.3
|
< 2.25.26
|
2.25.26 |
2023-11-06 |
—
|
CVE-2023-5525
The Limit Login Attempts Reloaded plugin contains a vulnerability in versions up to 2.25.25 where the toggle_auto_update() function called through AJAX lacks proper permission verification. An authenticated attacker possessing a valid nonce could exploit this flaw to enable or disable automatic plugin updates without proper authorization. This vulnerability allows unauthorized modification of plugin settings by users with minimal access levels.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings