Record summary

CVE-2022-1029 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.

Description

The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Limit Login Attempts

CVE List4.0.72 to < 4.0.72affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLimit Login Attempts - Stored Cross-Site ScriptingCVSS 4.8

Limit Login Attempts WordPress plugin < 4.0.72 contains a stored cross-site scripting caused by unsanitized and unescaped settings, letting malicious administrators inject Javascript code, exploit requires administrator privileges.

Impact

Attackers with administrator privileges can execute malicious Javascript in the context of the site, potentially stealing cookies or hijacking user sessions.

Remediation

Update to version 4.0.72 or later.

WeaknessesCWE-79
Authorstheamanrawat
Template tagscvecve2022wordpresswpwp-pluginminiorange-limit-login-attemptsxssauthenticated
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Source: ProjectDiscovery

References

2