VYPR

DoLogin Security

by WordPress

CVEs (5)

  • CVE-2023-4800MedOct 16, 2023
    risk 0.42cvss 6.5epss 0.01

    The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users.

  • CVE-2023-4549MedSep 25, 2023
    risk 0.40cvss 6.1epss 0.01

    The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.

  • CVE-2023-46608MedJan 2, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WPDO DoLogin Security dologin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DoLogin Security: from n/a through <= 3.7.1.

  • CVE-2023-4631MedSep 25, 2023
    risk 0.34cvss 5.3epss 0.01

    The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.

  • CVE-2026-14495HigJul 8, 2026
    risk 0.00cvss 8.8epss 0.01

    The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.3. The vulnerability exists because `dologin\s::rrand()` seeds the Mersenne Twister with `mt_srand((double) microtime() *…