DoLogin Security Unauthenticated Stored Cross-Site Scripting Vulnerability (CVE-2023-4549) — High Severity

Overview

The DoLogin Security WordPress plugin has a serious security flaw, identified as a Stored Cross-Site Scripting (XSS) vulnerability. This means that an attacker could inject malicious code into your website through the login form. Since the plugin doesn’t properly clean up IP addresses from the X-Forwarded-For header, this malicious code can get saved and later executed by unsuspecting users who visit your site.

CVE Details

Product Name: DoLogin Security WordPress plugin
Published: September 25, 2023
Severity: High (CVSS: 8.8)
Status: Analyzed

Affected Products

This vulnerability affects versions of the DoLogin Security WordPress plugin older than 3.7. If you are running an earlier version, your website could be at risk.

Current Status

This vulnerability has been “Analyzed,” meaning its details and impact are well understood by security researchers.

Severity Level

Rated as High severity with a CVSS score of 8.8, this vulnerability poses a significant risk. High severity issues can allow attackers to take control of user sessions, deface websites, or redirect users to malicious sites, potentially leading to data theft or further compromises without requiring any special permissions from the attacker.

Possible Solutions

The good news is that a fix is available. To protect your WordPress site, it is crucial to update your DoLogin Security plugin to version 3.7 or newer immediately. Regularly updating your plugins is a fundamental security practice that helps prevent many common attacks and keeps your website secure.

References

https://wpscan.com/vulnerability/8aebead0-0eab-4d4e-8ceb-8fea0760374f
https://wpscan.com/vulnerability/8aebead0-0eab-4d4e-8ceb-8fea0760374f

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.