Overview
The DoLogin Security WordPress plugin has a serious security flaw, identified as a Stored Cross-Site Scripting (XSS) vulnerability. This means that an attacker could inject malicious code into your website through the login form. Since the plugin doesn’t properly clean up IP addresses from the X-Forwarded-For header, this malicious code can get saved and later executed by unsuspecting users who visit your site.
CVE Details
Product Name: DoLogin Security WordPress plugin
Published: September 25, 2023
Severity: High (CVSS: 8.8)
Status: Analyzed
Affected Products
This vulnerability affects versions of the DoLogin Security WordPress plugin older than 3.7. If you are running an earlier version, your website could be at risk.
Current Status
This vulnerability has been “Analyzed,” meaning its details and impact are well understood by security researchers.
Severity Level
Rated as High severity with a CVSS score of 8.8, this vulnerability poses a significant risk. High severity issues can allow attackers to take control of user sessions, deface websites, or redirect users to malicious sites, potentially leading to data theft or further compromises without requiring any special permissions from the attacker.
Possible Solutions
The good news is that a fix is available. To protect your WordPress site, it is crucial to update your DoLogin Security plugin to version 3.7 or newer immediately. Regularly updating your plugins is a fundamental security practice that helps prevent many common attacks and keeps your website secure.
References
https://wpscan.com/vulnerability/8aebead0-0eab-4d4e-8ceb-8fea0760374f
https://wpscan.com/vulnerability/8aebead0-0eab-4d4e-8ceb-8fea0760374f

