wpbrigade loginpress CVE Vulnerabilities (4)

CVEs: 4 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting wpbrigade loginpress (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-41839 Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings. [email protected] 5.3 0.48% 2022-11-18 2024-11-21
CVE-2022-0347 The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting [email protected] 6.1 0.79% 2022-03-07 2024-11-21
CVE-2019-15872 The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. [email protected] 9.8 2.21% 2019-09-03 2024-11-21
CVE-2019-15871 The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings. [email protected] 4.3 0.89% 2019-09-03 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence