CVE-2024-10097
- EPSS 0.23%
- Veröffentlicht 05.11.2024 07:15:13
- Zuletzt bearbeitet 06.11.2024 19:14:22
The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This makes ...
CVE-2023-2296
- EPSS 0.12%
- Veröffentlicht 30.05.2023 08:15:10
- Zuletzt bearbeitet 10.01.2025 18:15:19
The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2022-45079
- EPSS 0.07%
- Veröffentlicht 22.05.2023 10:15:11
- Zuletzt bearbeitet 21.11.2024 07:28:44
Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.
CVE-2022-45084
- EPSS 0.09%
- Veröffentlicht 24.04.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 07:28:44
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.
CVE-2020-27615
- EPSS 86.34%
- Veröffentlicht 21.10.2020 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:28
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
CVE-2018-11366
- EPSS 3.21%
- Veröffentlicht 22.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:14
init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.
CVE-2017-12650
- EPSS 0.6%
- Veröffentlicht 07.08.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
CVE-2017-12651
- EPSS 0.12%
- Veröffentlicht 07.08.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.