CVE-2021-24328

The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:clogica:wp_login_security_and_history:*:*:*:*:*:wordpress:*:*

Information

Published : 2021-06-01 07:15

Updated : 2022-07-29 09:18


NVD link : CVE-2021-24328

Mitre link : CVE-2021-24328


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

clogica

  • wp_login_security_and_history