Limit Login Attempts
Limit Login Attempts has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2023; all 3 are fixed as of September 2026. Their average CVSS score is 7.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Improper Authentication.
Every one of the 3 issues recorded for Limit Login Attempts has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Limit Login Attempts is installed on roughly 300,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.2.11.
CVE-2012-10001Limit Login Attempts <= 1.7.0 - Brute Force Bypass
Read the full analysisVulnerability Records
Limit Login Attempts
Author
Automattic
Limit the number of login attempts possible both through normal login as well as using auth cookies. By default WordPress allows unlimited login attempts either through the login page or by sending special cookies. This allows passwords (or hashes) to be brute-force cracked with relative ease. Limit Login Attempts blocks an Internet address from making further attempts after a specified limit on retries is reached, making a brute-force attack difficult or impossible. Features Limit the number of retry attempts when logging in (for each IP). Fully customizable Limit the number of attempts to log in using auth cookies in same way Informs user about remaining retries or lockout time on login page Optional logging, optional email notification Handles server behind reverse proxy It is possible to whitelist IPs using a filter. But you probably shouldn’t. 🙂 Translations: Bulgarian, Brazilian Portuguese, Catalan, Chinese (Traditional), Czech, Dutch, Finnish, French, German, Hungarian, Norwegian, Persian, Romanian, Russian, Spanish, Swedish, Turkish Plugin uses standard actions and filters only.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C