CVE · Medium

CVE-2023-5525 — Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-5525 Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26 Missing Authorization Medium 4.3 < 2.25.26 2.25.26 2023-11-06

CVE-2023-5525

The Limit Login Attempts Reloaded plugin contains a vulnerability in versions up to 2.25.25 where the toggle_auto_update() function called through AJAX lacks proper permission verification. An authenticated attacker possessing a valid nonce could exploit this flaw to enable or disable automatic plugin updates without proper authorization. This vulnerability allows unauthorized modification of plugin settings by users with minimal access levels.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.