WPS Limit Login < 1.4.6.1 - Authorization Bypass via IP Spoofing
2019-07-23 00:00
Julio PotierStrategic Overview
StatusPatched in 1.4.6.1
Affected PluginWPS Limit Login
Affected Version
< 1.4.6.1CVSS9.8Critical
CVE
N/AVulnerability Overview
The WPS Limit Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.6. This is due to flawed implementation of the get_address() method. This makes it possible for unauthenticated attackers to run automated scripts to brute force passwords by changing the supplied IP Address in the HTTP header of the request. .
Technical Analysis
REMEDIATION: Update to version 1.4.6.1, or a newer patched version --- IDENTIFIER: CWE-307 (Improper Restriction of Excessive Authentication Attempts) The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C