SQL Injection Vulnerabilities in WP Limit Login Attempts Plugin by WordPress
CVE-2015-6829

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
16 September 2015

What is CVE-2015-6829?

The WP Limit Login Attempts plugin for WordPress contains multiple SQL injection vulnerabilities located in the getip function within wp-limit-login-attempts.php. These vulnerabilities allow remote attackers to execute arbitrary SQL commands by manipulating the X-Forwarded-For or Client-IP HTTP headers. Ensuring that this plugin is updated to version 2.0.1 or later is essential to protect your WordPress site from potential attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.