6.5
CVSSv3

CVE-2023-4800

Published: 16/10/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The DoLogin Security WordPress plugin prior to 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users.

Vulnerable Product Search on Vulmon Subscribe to Product

wpdo dologin security

Github Repositories

Repository for CVE-2023-4800 vulnerability.

CVE ID: CVE-2023-4800 Vulnerability Type: Sensitive Data Exposure Description: The DoLogin Security plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dashboard widget in versions up to, and including, 37 This makes it possible for authenticated attackers to view the login attempts log Steps to reproduce: Enable the plu