Vulnerabilities > CVE-2023-4549 - Unspecified vulnerability in Wpdo5Ea Dologin Security

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
wpdo5ea

Summary

The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.

Vulnerable Configurations

Part Description Count
Application
Wpdo5Ea
1