CRITICAL🇵🇱 Wersja polska

CVE-2015-9335

CVSS 9.8v3.0pub. 2019-08-22upd. 2024-11-21

The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Bestwebsoft Limit Attempts

    APP
    Bestwebsoft
    < 1.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2017-2171MEDIUM6.1same product

Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Conta...

CVE-2022-3393CRITICAL9.8PL ✓same vendor

CSV Injection w pluginie Post To CSV by BestWebSoft dla WordPress

CVE-2015-9325CRITICAL9.8PL ✓same vendor

SQL injection w pluginie Visitors Online dla WordPress

CVE-2024-13908HIGH7.2same vendor

The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type ...

CVE-2024-35678HIGH8.5same vendor

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebS...