Loginpress
Wpbrigade · 4 CVEs
CVE-2022-41839
MEDIUM
WordPress LoginPress plugin <= 1.6.2 - Broken Access Control vulnerability
Nov 18, 2022
CVE-2022-0347
MEDIUM
LoginPress < 1.5.12 - Reflected Cross-Site Scripting
Mar 7, 2022
CVE-2019-15871
MEDIUM
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
Sep 3, 2019
CVE-2019-15872
CRITICAL
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
Sep 3, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-41839 | WordPress LoginPress plugin <= 1.6.2 - Broken Access Control vulnerability | MEDIUM | 0.51% | Nov 18, 2022 |
| CVE-2022-0347 | LoginPress < 1.5.12 - Reflected Cross-Site Scripting | MEDIUM | 0.80% | Mar 7, 2022 |
| CVE-2019-15871 | The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings. | MEDIUM | 0.89% | Sep 3, 2019 |
| CVE-2019-15872 | The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. | CRITICAL | 2.21% | Sep 3, 2019 |
Showing 1 to 4 of 4 CVEs