Login Lockdown & Protection <= 2.17 - Unauthenticated Brute Force Protection Bypass via Email Address Login

Medium 5.3 CWE-307Fixed in 2.18
ID
WPSEC-2026-0556
Plugin
Login Lockdown & Protection (login-lockdown)
Affected
all versions before 2.18
Remediation
Update to 2.18 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-307
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Login Lockdown & Protection on WPSec AttackSurface
Fix released
Published

Description

The Login Lockdown & Protection plugin for WordPress is vulnerable to a brute force protection bypass in all versions up to, and including, 2.17. This is due to the plugin enforcing its IP lockout and login captcha only in its replacement for WordPress's username authenticator, which returns early once WordPress core's email address authenticator has already validated the credentials, and to failed login attempts being attributed to an account by username only. In versions 2.0 and later, a 'rest_route' query parameter on the login request also caused the plugin to skip the captcha and never trigger a lockout for the attempt. This makes it possible for unauthenticated attackers who know a user's email address to make unlimited password guesses against that account without being challenged by the captcha or stopped by the IP lockout.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0