Lucene search

K

Loginpress Security Vulnerabilities

cve
cve

CVE-2019-15871

The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.

4.3CVSS

5.6AI Score

0.001EPSS

2019-09-03 01:15 PM
56
cve
cve

CVE-2019-15872

The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.

9.8CVSS

9.9AI Score

0.002EPSS

2019-09-03 01:15 PM
60
cve
cve

CVE-2022-0347

The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

6.1CVSS

6AI Score

0.001EPSS

2022-03-07 09:15 AM
72
cve
cve

CVE-2022-41839

Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings.

5.3CVSS

5.2AI Score

0.001EPSS

2022-11-18 11:15 PM
37
2