# Login Lockdown & Protection <= 2.17 - Unauthenticated Brute Force Protection Bypass via Email Address Login

- **ID:** WPSEC-2026-0556
- **Plugin:** Login Lockdown & Protection (`login-lockdown`), https://wordpress.org/plugins/login-lockdown/
- **Affected versions:** all versions before 2.18
- **Fixed in:** 2.18 (Update to 2.18 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-307
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/login-lockdown
- **Fix released:** 2026-10-02
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0556/

## Description

The Login Lockdown & Protection plugin for WordPress is vulnerable to a brute force protection bypass in all versions up to, and including, 2.17. This is due to the plugin enforcing its IP lockout and login captcha only in its replacement for WordPress's username authenticator, which returns early once WordPress core's email address authenticator has already validated the credentials, and to failed login attempts being attributed to an account by username only. In versions 2.0 and later, a 'rest_route' query parameter on the login request also caused the plugin to skip the captcha and never trigger a lockout for the attempt. This makes it possible for unauthenticated attackers who know a user's email address to make unlimited password guesses against that account without being challenged by the captcha or stopped by the IP lockout.

## References

- https://wpsec.com/vuln/WPSEC-2026-0556/
- https://plugins.svn.wordpress.org/login-lockdown/tags/2.18/
- https://wordpress.org/plugins/login-lockdown/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0556/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
