Skip to content

Known CVE

Limit Login Attempts (Spam Protection) < 5.1 - SQL Injection

The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections.

CVE-2022-0787

Critical2022CVSS 9.8CWE-89

time-based-sqli · cve2022 · wpscan · sqli · wordpress · wp-plugin · wp · wp-limit-failed-login-attempts

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website