CVE-2024-1340
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Feb 29, 2024
Summary
CVE-2024-1340 is a vulnerability affecting the Login Lockdown plugin for WordPress. This issue allows authenticated attackers, with subscriber access and higher, to export sensitive information including whitelisted IP addresses and a global unlock key. The vulnerability stems from a missing capability check on the plugin's generate_export_file function, which is present in all versions up to and including 2.08. Successful exploitation grants attackers the ability to add their IP addresses to the whitelist, bypassing the plugin's security measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.