Limit Login Attempts WordPress plugin < 4.0.50 contains a stored cross-site scripting caused by not escaping IP addresses controlled via headers like X-Forwarded-For before outputting them in reports, letting unauthenticated attackers execute scripts in admin context.
id: CVE-2021-24657
info:
name: Limit Login Attempts WordPress - Stored Cross-site Scripting
aut
...