cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forlimit-login-attempts limit-login-attempts

Direction: ascending
Jun 07, 2024

Limit Login Attempts # CVE-2023-1861

CVE, Research URL

CVE-2023-1861

Application

Limit Login Attempts

Date
May 02, 2023
Research Description
The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
Affected versions
max 1.7.2.
Status
vulnerable

Limit Login Attempts # CVE-2012-10001

CVE, Research URL

CVE-2012-10001

Application

Limit Login Attempts

Date
Jan 06, 2021
Research Description
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
Affected versions
max 1.7.1.
Status
vulnerable

Limit Login Attempts # CVE-2023-1912

CVE, Research URL

CVE-2023-1912

Application

Limit Login Attempts

Date
Apr 06, 2023
Research Description
The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the plugin's settings page. This only works when the plugin prioritizes use of the X-FORWARDED-FOR header, which can be configured in its settings.
Affected versions
max 1.7.2.
Status
vulnerable
Aug 25, 2026

Limit Login Attempts # PSC-2026-64690

PSC, Research URL

PSC-2026-64690

Application

Limit Login Attempts

Date
Aug 25, 2026
Research Description
Login protection plugins operate directly on authentication requests, retry counters, lockouts, cookies, client addresses, and administrative notifications. Limit Login Attempts version 1.7.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64690, confirming that the review focused on retry tracking, IP handling, lockout enforcement, authentication cookie checks, configuration access, and safe logging of failed attempts.
Affected versions
Min 1.7.2, max 1.7.2.
Status
SAFE & CERTIFIED