Login Block Ips
by Gunkastudios
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1579 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2022 | The function check_is_login_page() uses headers for the IP check, which can be easily spoofed. | ||
| CVE-2022-3098 | Med | 0.28 | 4.3 | 0.00 | Sep 26, 2022 | The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |
- risk 0.49cvss 7.5epss 0.01
The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.
- risk 0.28cvss 4.3epss 0.00
The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack