Vulnerabilities > Limit Login Attempts Project > Limit Login Attempts > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-03-28 CVE-2022-0787 Unspecified vulnerability in Limit Login Attempts Project Limit Login Attempts
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections
network
low complexity
limit-login-attempts-project
critical
9.8
2021-01-06 CVE-2012-10001 Improper Authentication vulnerability in Limit Login Attempts Project Limit Login Attempts
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
network
low complexity
limit-login-attempts-project CWE-287
critical
9.8