Known CVE
Limit Login Attempts (Spam Protection) < 5.1 - SQL Injection
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections.
CVE-2022-0787
Critical2022CVSS 9.8CWE-89
time-based-sqli · cve2022 · wpscan · sqli · wordpress · wp-plugin · wp · wp-limit-failed-login-attempts
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website