Vulnerability Description
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Loginizer | Loginizer | < 1.6.4 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2401010/loginizerPatchThird Party Advisory
- https://wpdeeply.com/loginizer-before-1-6-4-sqli-injection/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/10441Third Party Advisory
- https://www.zdnet.com/article/wordpress-deploys-forced-security-update-for-dangeThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2401010/loginizerPatchThird Party Advisory
- https://wpdeeply.com/loginizer-before-1-6-4-sqli-injection/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/10441Third Party Advisory
- https://www.zdnet.com/article/wordpress-deploys-forced-security-update-for-dangeThird Party Advisory
FAQ
What is CVE-2020-27615?
CVE-2020-27615 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
How severe is CVE-2020-27615?
CVE-2020-27615 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-27615?
Check the references section above for vendor advisories and patch information. Affected products include: Loginizer Loginizer.