Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-24328

The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.1%
CVSS Severity
CVSS v3 Score 6.2
CVSS v2 Score 3.5
References
Products affected by CVE-2021-24328


Contact Us

Shodan ® - All rights reserved