PT-2026-79371 · WordPress · Limit-Login-Attempts-Reloaded
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Limit Login Attempts Reloaded versions prior to 3.3.5
Description
The plugin fails to perform case-insensitive comparisons when checking logins against the username denylist and does not consider the account email address. This allows blocked accounts to bypass the restriction and authenticate successfully.
Recommendations
Update to version 3.3.5 or later.
Exploit
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Limit-Login-Attempts-Reloaded