Vulnerability Details CVE-2023-4549
The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.4%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2023-4549
-
cpe:2.3:a:wpdo5ea:dologin_security:*