WordPress Limit Login Attempts plugin <= 5.5 - SQL Injection vulnerability
CVE-2024-54234

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 December 2024

What is CVE-2024-54234?

The vulnerability within the Limit Login Attempts plugin for WordPress allows attackers to exploit improper neutralization of special elements within SQL commands. This SQL Injection flaw affects versions up to and including 5.5 and poses significant risks to websites relying on this feature for login security. Attackers could potentially execute arbitrary SQL commands, manipulate database queries, and gain unauthorized access to sensitive information. Website administrators should prioritize patching this vulnerability to maintain the security integrity of their platforms.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Limit Login Attempts <= 5.5

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.