S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 15, 2025

CVE-2022-1029 Scanner

CVE-2022-1029 Scanner - Cross-Site Scripting (XSS) vulnerability in Limit Login Attempts WordPress Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1029
4.8
CVSS

The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Limit Login Attempts
AFFECTED< 4.0.72SAFE ✓≥ 4.0.72
Updated Aug 22, 2026View on NVD →
Detail

Limit Login Attempts is a popular WordPress plugin used by site administrators to manage and limit the number of login attempts made on their WordPress sites. This helps in protecting sites from brute-force attacks and unauthorized access. The plugin is commonly used due to its effectiveness in securing WordPress logins. It is suitable for blogs, corporate sites, and e-commerce platforms built on WordPress. Site administrators deploy it to ensure login security and reduce the risk of unauthorized access. The plugin integrates seamlessly with WordPress, providing an additional layer of security without complicated setup.

The detected vulnerability is a stored Cross-Site Scripting (XSS) vulnerability. This occurs when an attacker successfully injects malicious scripts into a web application, which are stored and then executed in the browsers of users who visit the affected site. In this case, the vulnerability allows administrators with malicious intent to inject JavaScript code into the plugin settings. If exploited, this can lead to session hijacking or cookie theft, exposing sensitive user information.

The vulnerability exists in the settings page of the Limit Login Attempts WordPress plugin. Unsanitized and unescaped settings inputs allow for the injection of scripts. Particularly, the "referrer_1" parameter is vulnerable as it does not properly escape input values, enabling the execution of injected JavaScript when the settings page is accessed by any user. This opens the risk of stored XSS where malicious code persists across sessions and users.

Exploitation of this vulnerability allows attackers to execute arbitrary JavaScript in the context of the vulnerable site, potentially stealing cookies, session tokens, or performing actions on behalf of users. This can compromise user accounts and data integrity, resulting in unauthorized actions being performed. The impact is significant for site integrity, user confidence, and data security.

REFERENCES

Solution Advice
  • Update the Limit Login Attempts plugin to version 4.0.72 or later to patch the vulnerability.
  • Regularly check for and apply updates to plugins and themes to ensure security patches are implemented timely.
  • Restrict administrative access to trusted individuals to minimize the risk of insider threats.
  • Employ additional security measures such as Web Application Firewalls (WAFs) to detect and prevent XSS attacks.
  • Conduct regular security audits and pen-testing to discover and mitigate potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.