Skip to content

Known CVE

Limit Login Attempts WordPress - Stored Cross-site Scripting

Limit Login Attempts WordPress plugin < 4.0.50 contains a stored cross-site scripting caused by not escaping IP addresses controlled via headers like X-Forwarded-For before outputting them in reports, letting unauthenticated attackers execute scripts in admin context.

CVE-2021-24657

Medium2021CVSS 6.1CWE-79

cve2021 · wordpress · wp · wp-plugin · miniorange-limit-login-attempts · xss · authenticated

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website