Loginplus <= 1.2 - Missing Authorization
EntreBase Advisory: The Loginplus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Read more about this vulnerability: https://www.wordfence.com/threat-intel/vulnerabilities/id/581e1d70-0280-443b-b319-7047325866e4?source=api-prod