VYPR
Medium severity6.1NVD Advisory· Published May 22, 2018· Updated Jun 17, 2026

CVE-2018-11366

CVE-2018-11366

Description

init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • WordPress/Loginizerinferred2 versions
    >=1.3.8,<=1.3.9+ 1 more
    • (no CPE)range: >=1.3.8,<=1.3.9
    • (no CPE)range: >=1.3.8, <=1.3.9
  • cpe:2.3:a:loginizer:loginizer:1.3.8:*:*:*:*:wordpress:*:*+ 1 more
    • cpe:2.3:a:loginizer:loginizer:1.3.8:*:*:*:*:wordpress:*:*
    • cpe:2.3:a:loginizer:loginizer:1.3.9:*:*:*:*:wordpress:*:*

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.