S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0787 Scanner

CVE-2022-0787 scanner - SQL Injection vulnerability in Limit Login Attempts (Spam Protection)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0787
9.8
CVSS

The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Limit Login Attempts (Spam Protection)
AFFECTED< 5.1SAFE ✓≥ 5.1
Updated Aug 22, 2026View on NVD →
Detail

The Limit Login Attempts (Spam Protection) plugin for WordPress is designed to protect websites by limiting the number of login attempts from a single IP address, thereby preventing brute force attacks. It's widely used by WordPress site administrators to enhance security and mitigate unauthorized access risks. The plugin is especially useful for websites that face frequent login attempts and is a critical security measure in protecting user data and access. Developers and site administrators deploy this plugin to ensure that their sites remain secure against one of the most common types of cybersecurity threats. Its straightforward implementation and effectiveness make it a popular choice in the WordPress community.

The technical flaw resides in the way the Limit Login Attempts (Spam Protection) plugin processes certain parameters via AJAX actions. Specifically, it fails to properly sanitize and escape user inputs before incorporating them into SQL statements. This oversight allows attackers to inject malicious SQL code through crafted requests to the 'WPLFLA_get_log_data' AJAX action. The vulnerability is triggered when the SQL code is executed by the plugin's backend, leading to potential SQL Injection attacks. Vulnerable endpoints include the 'admin-ajax.php' file, with parameters like 'order[][column]' and 'columns[][data]' being particularly susceptible.

Successful exploitation of this vulnerability could lead to a range of adverse effects, including unauthorized access to sensitive information stored in the website's database, such as user credentials and personal data. Attackers could also modify or delete data, disrupting the website's functionality or defacing it. In severe cases, it could lead to complete control over the affected website, allowing attackers to redirect visitors, deploy malicious content, or leverage the site's resources for further attacks. The breach of data confidentiality, integrity, and availability highlights the critical impact of this vulnerability.

By joining the S4E platform, users gain access to comprehensive security scanning capabilities that can identify and alert on vulnerabilities like the SQL Injection in the Limit Login Attempts (Spam Protection) plugin. Our platform provides detailed reports, actionable insights, and guidance on mitigating identified vulnerabilities, helping you to proactively secure your digital assets against emerging threats. With our service, you can ensure continuous monitoring and protection of your websites, enhancing your cybersecurity posture and maintaining the trust of your users.

 

References

Solution Advice
  1. Update the Limit Login Attempts (Spam Protection) plugin to version 5.1 or later immediately.
  2. Regularly check for and apply updates to all WordPress plugins and themes.
  3. Implement and maintain a robust input validation and sanitization process to prevent SQL injection vulnerabilities.
  4. Use a web application firewall (WAF) to detect and block malicious requests.
  5. Conduct regular security assessments and penetration testing to identify and address potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.