RULE(RULE ID:335456)

Rule General Information
Release Date: 2021-12-20
Rule Name: WordPress Loginizer SQL Injection Vulnerability (CVE-2017-12650)
Severity:
CVE ID:
Rule Protection Details
Description: SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://blog.wpscans.com/sql-injection-and-csrf-security-vulnerability-in-loginizer/
https://sv.wordpress.org/plugins/loginizer/#developers
https://wpvulndb.com/vulnerabilities/8883
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://sv.wordpress.org/plugins/loginizer/#developers