VendorsLimit Login Attempts Projectlimit_login_attemptsall versions
Vulnerabilities

Limit Login Attempts Project Limit Login Attempts

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-0787
Limit Login Attempts (Spam Protection) < 5.1 - Unauthenticated SQLi
Published 2022-03-28 · Modified
9.8EPSS 0.086
CVE-2012-10001
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
Published 2021-01-06 · Modified
9.8EPSS 0.025
CVE-2023-1912
Limit Login Attempts <= 1.7.1 - Unauthenticated Stored Cross-Site Scripting
Published 2023-04-06 · Modified
7.2EPSS 0.008
CVE-2021-24657
Limit Login Attempts < 4.0.50 - Unauthenticated Stored Cross-Site Scripting
Published 2021-09-20 · Modified
6.1EPSS 0.016
CVE-2023-1861
Limit Login Attempts < 1.7.2 - Subscriber+ Stored XSS
Published 2023-05-02 · Modified
5.4EPSS 0.288