CVE-2020-35590 Information
Jun 07, 2022
cve
Description
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address a malicious user is not limited to perform a brute force attack because the client IP header accepts any arbitrary string. When randomizing the header input the login count does not ever reach the maximum allowed retries.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://n4nj0.github.io/advisories/wordpress-plugin-limit-login-attempts-reloaded/ https://wordpress.org/plugins/limit-login-attempts-reloaded/#developers
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: