BruteGuard – Brute Force Login Protection
BruteGuard – Brute Force Login Protection has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for BruteGuard – Brute Force Login Protection has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by 0xd4rk5id3. BruteGuard – Brute Force Login Protection is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.9.16.
CVE-2025-39408BruteGuard – Brute Force Login Protection <= 0.1.4 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

BruteGuard – Brute Force Login Protection
Author
EverPress
BruteGuard is a cloud powered brute force login protection that shields your site against botnet attacks. Botnets and other malicious scripts attack millions of websites each and every day BruteGuard is a brute force attack prevention plugin that guards you against botnets by connecting its users to track failed login attempts across all WordPress installations that use the plugin. Once you activate BruteGuard you become part of a inter-connected protection layer against botnet attacks. BruteGuard logs failed attempts network wide Our plugin logs and blocks IPs across the entire network. The more users use BruteGuard the safer the whole network including you gets. BruteGuard fully supports multi sites and is an additional security layer so can be used with any other security plugin.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C