Vulnerabilities and security researches forlimit-login-attempts limit-login-attempts
Direction: ascendingJun 07, 2024
Limit Login Attempts # CVE-2023-1861
- CVE, Research URL
- Home page URL
- Application
- Date
- May 02, 2023
- Research Description
- The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
- Affected versions
-
max 1.7.2.
- Status
-
vulnerable
Limit Login Attempts # CVE-2012-10001
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 06, 2021
- Research Description
- The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
- Affected versions
-
max 1.7.1.
- Status
-
vulnerable
Limit Login Attempts # CVE-2023-1912
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 06, 2023
- Research Description
- The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the plugin's settings page. This only works when the plugin prioritizes use of the X-FORWARDED-FOR header, which can be configured in its settings.
- Affected versions
-
max 1.7.2.
- Status
-
vulnerable
Aug 25, 2026
Limit Login Attempts # PSC-2026-64690
- PSC, Research URL
- Home page URL
- Application
- Date
- Aug 25, 2026
- Research Description
- Login protection plugins operate directly on authentication requests, retry counters, lockouts, cookies, client addresses, and administrative notifications. Limit Login Attempts version 1.7.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64690, confirming that the review focused on retry tracking, IP handling, lockout enforcement, authentication cookie checks, configuration access, and safe logging of failed attempts.
- Affected versions
-
Min 1.7.2, max 1.7.2.
- Status
-
SAFE & CERTIFIED