{
 "id": "WPSEC-2026-0556",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0556/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0556/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0556/index.md",
 "title": "Login Lockdown & Protection <= 2.17 - Unauthenticated Brute Force Protection Bypass via Email Address Login",
 "description": "The Login Lockdown & Protection plugin for WordPress is vulnerable to a brute force protection bypass in all versions up to, and including, 2.17. This is due to the plugin enforcing its IP lockout and login captcha only in its replacement for WordPress's username authenticator, which returns early once WordPress core's email address authenticator has already validated the credentials, and to failed login attempts being attributed to an account by username only. In versions 2.0 and later, a 'rest_route' query parameter on the login request also caused the plugin to skip the captcha and never trigger a lockout for the attempt. This makes it possible for unauthenticated attackers who know a user's email address to make unlimited password guesses against that account without being challenged by the captcha or stopped by the IP lockout.",
 "plugin": {
  "slug": "login-lockdown",
  "name": "Login Lockdown & Protection",
  "full_name": "Login Lockdown & Protection",
  "wordpress_org": "https://wordpress.org/plugins/login-lockdown/",
  "advisories_url": "https://wpsec.com/vuln/plugin/login-lockdown/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/login-lockdown"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-307"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "2.18",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 2.18"
  ]
 },
 "introduced_in": null,
 "fixed_in": "2.18",
 "remediation": "Update to 2.18 or later.",
 "fix_released": "2026-10-02T13:48:05+00:00",
 "published": "2026-10-07T15:58:04+00:00",
 "updated": "2026-10-07T15:30:52.289438+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0556/",
  "https://plugins.svn.wordpress.org/login-lockdown/tags/2.18/",
  "https://wordpress.org/plugins/login-lockdown/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/login-lockdown",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}