cleantalk
Vulnerabilities and Security Researches

Limit Login Attempts Reloaded, CVE-2023-5525

CVE, Research URL

CVE-2023-5525

Published on
Nov 27, 2023
Research Description
The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.
Affected versions
max 2.25.26.
Status
vulnerable