WordPress · Login & Register Forms · CVE-2026-18469
**Name of the Vulnerable Software and Affected Versions**
Login & Register Forms versions prior to 4.0.2
**Description**
When the verification-code reset mode is enabled, the plugin fails to enforce password reset attempt limits using a server-derived value. Instead, it relies on client-controlled data for both the verification code and the per-source attempt counter. This allows unauthenticated attackers to reset the attempt limit and brute-force the verification code to take over any account, including those with administrator privileges.
**Recommendations**
Update Login & Register Forms to version 4.0.2 or later.