{"error":0,"message":null,"data":{"name":"Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention","plugin":"limit-login-attempts-reloaded","link":"https:\/\/wordpress.org\/plugins\/limit-login-attempts-reloaded\/","latest":"1789635960","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"2cab73aa812a20dd76a897944cb984ceb51da52878b0f570cab4be02071961a2","name":"Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-35589","name":"CVE-2020-35589","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-35589","description":"[en] The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin\/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims.","date":"2020-12-21"},{"id":"6896194b33b7deb8ab64a283c37c859a30d140a4","name":"Limit Login Attempts Reloaded <= 2.15.2 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/limit-login-attempts-reloaded\/limit-login-attempts-reloaded-2152-reflected-cross-site-scripting","description":"The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin\/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims.","date":"2020-12-14"},{"id":"6d30da09-df37-49be-bb46-0e0fec90850f","name":"Limit Login Attempts Reloaded &lt; 2.16.0 - Authenticated Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/6d30da09-df37-49be-bb46-0e0fec90850f","description":"The plugin does not properly sanitise user input in its options page, which could allow attackers to perform XSS attacks against logged in administrator by making them open a malicious URL\r\n\r\nThe issue was partially fixed in 2.15.1, and fully remediated in 2.16.0","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"24ed1391a17692ca7ef43c290fd28f7bbea2de7b155c0aa968528b45c2f9a13a","name":"Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-35590","name":"CVE-2020-35590","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-35590","description":"[en] LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited to perform a brute force attack, because the client IP header accepts any arbitrary string. When randomizing the header input, the login count does not ever reach the maximum allowed retries.","date":"2020-12-21"},{"id":"fa73661b46050f1b275c6d72893c883bfd8f8750","name":"Limit Login Attempts Reloaded <= 2.17.3 - Login Rate Limiting Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/limit-login-attempts-reloaded\/limit-login-attempts-reloaded-2173-login-rate-limiting-bypass","description":"LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited to perform a brute force attack, because the client IP header accepts any arbitrary string. When randomizing the header input, the login count does not ever reach the maximum allowed retries.","date":"2020-12-14"},{"id":"66dbc019-ba09-4a3f-a16d-fa04eea99ea8","name":"Limit Login Attempts Reloaded &lt; 2.17.4 - Login Rate Limiting Bypass","link":"https:\/\/wpscan.com\/vulnerability\/66dbc019-ba09-4a3f-a16d-fa04eea99ea8","description":"When the plugin is configured with a custom header in its Trusted IP Origins setting (e.g X-Forwarded-For), attackers could bypass the protection offered by tampering the header sent in requests.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-307","name":"Improper Restriction of Excessive Authentication Attempts","description":"The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame."}]}},{"uuid":"0fd6bc058774389f41e5636df21db3595ac8aa48a1199eed711ee5b962394f22","name":"Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.16.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.16.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"56bacbe439048a4c63accefbe3c6a67dde1d693a","name":"WordPress Limit Login Attempts Reloaded plugin <= 2.15.2 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/limit-login-attempts-reloaded\/vulnerability\/wordpress-limit-login-attempts-reloaded-plugin-2-15-2-authenticated-reflected-cross-site-scripting-xss-vulnerability","description":"Authenticated Reflected Cross-Site Scripting (XSS) vulnerability found by n4nj0 in WordPress Limit Login Attempts Reloaded plugin (versions <= 2.15.2).","date":"2020-12-21"}],"impact":[]},{"uuid":"95f930ec3715080fd88fa1b03877d60f04480b6842350258c717a90f5e299382","name":"Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9591a3917a4bed8a1ec40baf07ab49d89ab1d3fa","name":"WordPress Limit Login Attempts Reloaded plugin <= 2.17.3 - Login Rate Limiting Bypass vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/limit-login-attempts-reloaded\/vulnerability\/wordpress-limit-login-attempts-reloaded-plugin-2-17-3-login-rate-limiting-bypass-vulnerability","description":"Login Rate Limiting Bypass vulnerability found by n4nj0 in WordPress Limit Login Attempts Reloaded plugin (versions <= 2.17.3).","date":"2020-12-21"}],"impact":[]},{"uuid":"2512818d9125d80c201e78d805092101c4016c944e0f643edc87dd880f5c2f88","name":"Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.26","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.25.26","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-5525","name":"CVE-2023-5525","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-5525","description":"[en] The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.","date":"2023-11-27"},{"id":"3b4d647b00c760cc537e3d50e313a34ada1d2695","name":"Limit Login Attempts Reloaded <= 2.25.25 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/limit-login-attempts-reloaded\/limit-login-attempts-reloaded-22525-missing-authorization","description":"The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the toggle_auto_update() function hooked via AJAX in all versions up to, and including, 2.25.25. This makes it possible for authenticated attackers, with access to a valid nonce, to toggle auto-updates for the plugin on and off.","date":"2023-11-06"},{"id":"654bad15-1c88-446a-b28b-5a412cc0399d","name":"Limit Login Attempts Reloaded &lt; 2.25.26 - Admin+ Missing Authorization to Toggle Plugin Auto-Update","link":"https:\/\/wpscan.com\/vulnerability\/654bad15-1c88-446a-b28b-5a412cc0399d","description":"The plugin is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"dcbc7115816e12b0cfb6a8e986cab1c37bb3c9dacccc0cae8d14a085e82c6bbc","name":"Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.25.27","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.25.27","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6934","name":"CVE-2023-6934","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6934","description":"[en] The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-01-11"},{"id":"99e7ecb95122bee70d380c6e8aa354d885c5bdd1","name":"Limit Login Attempts Reloaded <= 2.25.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/limit-login-attempts-reloaded\/limit-login-attempts-reloaded-22526-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-20"},{"id":"8ae24616b33d2caae7b649ea415b70b23ccffc40","name":"WordPress  Limit Login Attempts Reloaded Plugin  <= 2.25.26 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/limit-login-attempts-reloaded\/vulnerability\/wordpress-limit-login-attempts-reloaded-plugin-2-25-26-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"Update the WordPress Limit Login Attempts Reloaded plugin to the latest available version (at least 2.25.27).\nHung -mov Nguyen discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Limit Login Attempts Reloaded Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 2.25.27.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-21"},{"id":"b554fc84-0e84-41b0-ba67-dd4a1dce9084","name":"Limit Login Attempts Reloaded &lt; 2.25.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/wpscan.com\/vulnerability\/b554fc84-0e84-41b0-ba67-dd4a1dce9084","description":"The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"14fe8483f82d130f0dbe98063eb7c4b77a0b07a0ba381c5c4e6fe4b944f6bcf1","name":"Limit Login Attempts Security &#8211; Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 3.3.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-18356","name":"CVE-2026-18356","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-18356","description":"[en] The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.","date":"2026-08-21"},{"id":"9f38540a80f7c31604880acd943a1970959cc22f","name":"WordPress Limit Login Attempts Reloaded Plugin < 3.3.5 is vulnerable to Bypass Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/limit-login-attempts-reloaded\/vulnerability\/wordpress-limit-login-attempts-security-plugin-3-3-5-username-denylist-bypass-vulnerability","description":"<p>WordPress Limit Login Attempts Reloaded Plugin < 3.3.5 is vulnerable to Bypass Vulnerability<\/p><p>Software: Limit Login Attempts Reloaded<\/p><p>Fixed in version 3.3.5 <\/p><p>Affected Version < 3.3.5<\/p><p>CVE: CVE-2026-18356<\/p>","date":"2026-08-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"3.7","severity":"l","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"3.7","severity":"low","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-184","name":"Incomplete List of Disallowed Inputs","description":"The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1787722369"}