Unauthenticated Stored Cross-Site Scripting in WPS Limit Login WordPress Plugin (CVE-2026-93622)  – 2026092808

SeverityHIGH
Threat CategoryVulnerability – Stored Cross-Site Scripting (CWE-79)
Affected PlatformsWordPress sites running the WPS Limit Login plugin (by NicolasKulka), all versions up to and including 1.5.9.3
CVECVE-2026-93622
CVSS7.1 HIGH (v3.1)

1. Overview

Security researchers at Patchstack have disclosed an unauthenticated stored cross-site scripting (XSS) vulnerability in WPS Limit Login, a WordPress plugin that limits failed login attempts to protect against brute-force attack with more than 100,000 active installations. Tracked as CVE-2026-93622, the flaw allows remote, unauthenticated attackers to inject malicious HTML or JavaScript code into the plugin’s failed-login log. When a site administrator views the log in the WordPress dashboard, the payload executes automatically within the context of their authenticated session. 

The vulnerability affects all versions up to and including 1.5.9.3 and is fixed in version 1.5.9.4. The vulnerability was reported by security researcher Ananda Dhakal through the Patchstack Bug Bounty Program.

2. Who is Affected

Any WordPress site using WPS Limit Login version 1.5.9.3 or earlier is affected. WordPress is widely used across Bhutanese government offices, agencies, businesses, media outlets, and individuals, and login-limiter plugins of this kind are a common hardening measure. A site is exposed whenever an administrator opens the plugin’s failed-login log while a malicious entry is present.

BtCIRT has not received any reports of confirmed exploitation within Bhutan, and there are no public reports of this vulnerability being exploited in the wild at the time of writing. The severity is nonetheless assessed as HIGH for the following factors:

  • Zero Authentication Required:  Anyone capable of reaching the site’s login page (`wp-login.php`) can submit a payload without credentials.
  • Passive Execution (Stored XSS): Attackers do not need to trick the target into clicking external links; simply viewing the routine lockout log triggers the script.
  • Session Hijacking & Scope Elevation: Scripts executing within an administrator’s browser session gain full privilege parity, allowing attackers to create new admin accounts, install malicious plugins or backdoors, modify core files, and fully compromise the target site.

Also, the plugin is installed on more than 100,000 sites, and full technical details plus a fixed version are now public, which makes affected sites easy to identify and target.

3. How the [Threat/Vulnerability/Attack] Works

  1. Stage 1 – Root Cause : When a login attempt fails, WPS Limit Login stores the submitted username in its lockout log. The plugin does not sanitise or escape this attacker-controlled value before saving it and rendering it in the dashboard (Improper Neutralization of Input During Web Page Generation – CWE-79).
  2. Stage 2 – Injection: An unauthenticated attacker sends a failed login request to the site (for example to wp-login.php) using a username crafted to contain HTML or JavaScript instead of a real account name. No valid credentials are needed. 
  3. Stage 3 – Trigger: The malicious username is now stored in the lockout log. When a site administrator later opens that log in the WordPress dashboard, the browser renders the stored payload and executes it within the administrator’s authenticated session. 
  4. Stage 4 – Impact: Running in the administrator’s session, the script can act as that administrator: create a new administrator account, install or modify a plugin or theme to plant a persistent backdoor, change site settings, or read and exfiltrate data visible to the admin. A low-privilege injection can therefore lead to full compromise of the website.
  5. Impact: The vendor has released WPS Limit Login 1.5.9.4, which properly escapes the failed-login username so it can no longer execute as script. Patchstack, acting as CVE Numbering Authority, published CVE-2026-93622 on 23 September 2026.

4. Indicators to Watch For

Audit your systems for the following signs of vulnerability or active exploitation:

  • The installed plugin version is 1.5.9.3 or earlier. Check on the wp-admin Plugins page, or with: wp plugin get wps-limit-login –field=version
  • Database records or log views containing HTML/JavaScript tags (e.g., `<script>`, `onerror=`, `onload=`, or URL-encoded equivalents like `%3Cscript%3E`).
  • Web server access logs showing POST requests to wp-login.php with unusually long or HTML-bearing values in the log= (username) field.
  • Unrecognized administrator user accounts, unexpected file modifications in `wp-content/plugins/` or `wp-content/themes/`, or changed site settings that appear shortly after an administrator viewed the failed-login log.
  • Unexpected outbound requests from the browser of an administrator who recently opened the plugin’s log page.

5. Recommendations

  • Immediately update WPS Limit Login to version 1.5.9.4 or later on every WordPress site as the primary fix. Verify the version afterwards.
  • If the plugin cannot be updated immediately, deactivate and remove it and rely on another maintained rate-limiting or brute-force protection control until it can be updated. 
  • Before opening the lockout log in a browser on an unpatched site, inspect existing entries safely first, for example from the database or with WP-CLI (wp db query), so a stored payload does not execute in an admin session.
  • If suspicious log entries or signs of compromise are found, treat the site as breached: audit all administrator and user accounts, remove any unrecognised accounts, review installed plugins and themes and file changes, rotate all administrator passwords and secret keys, and restore from a known-good backup where necessary.
  • Restrict access to the WordPress dashboard and login page where feasible (IP allow-listing, VPN, or a web application firewall) and keep WordPress core, themes, and all plugins updated.

5.2. For individuals (if applicable):

  • If you run a personal or small WordPress site with WPS Limit Login, update it to version 1.5.9.4 or later from the Plugins screen. Enable automatic updates for the plugin if you can.
  • If you do not actively use the plugin, deactivate and delete it.
  • Avoid opening the plugin’s failed-login log on an unpatched site, and if anything on your site looks changed after doing so, change your administrator password immediately and seek help.

6. Reporting

If you suspect your organization, device or account has been affected by this threat, or observe activity matching this pattern, please report it to BtCIRT at cirt@btcirt.bt

7. Sources and References

  1. Patchstack – WordPress WPS Limit Login Plugin <= 1.5.9.3 Unauthenticated Stored Cross-Site Scripting (CVE-2026-93622) (23 September 2026). https://patchstack.com/database/wordpress/plugin/wps-limit-login/vulnerability/wordpress-wps-limit-login-plugin-1-5-9-3-cross-site-scripting-xss-vulnerability
  2. CVE-2026-93622 – CVE Record (assigned by Patchstack) (23 September 2026). https://www.cve.org/CVERecord?id=CVE-2026-93622
  3. NVD – CVE-2026-93622 Detail (23 September 2026).
    https://nvd.nist.gov/vuln/detail/CVE-2026-93622
  4. WPS Limit Login – WordPress.org plugin page and changelog (fix in 1.5.9.4) (September 2026). https://wordpress.org/plugins/wps-limit-login/
Scroll to Top