Login Lockdown & Protection

Login Lockdown & Protection has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 5 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.

The most common weakness is Missing Authorization, behind 2 of the records (40%). Other recurring categories include SQL Injection, Use Of Insufficiently Random Values.

Every one of the 5 issues recorded for Login Lockdown & Protection has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, one record each. Login Lockdown & Protection is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage100%
Open

0

Fixed

5

Get automatic notifications for all Login Lockdown & Protection vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2

Login Lockdown <= 2.06 - Authenticated (Administrator+) SQL Injection

Read the full analysis

Vulnerability Records

5 records
Login Lockdown & Protection banner
Latestv2.17

Login Lockdown & Protection

WebFactory

Author

WebFactory

4.3(61)
86/100
Last Updated
2026-08-16 (28d ago)
Active Installs
100,000+
Downloads
2,062,717
Requires WP
4.0+
Requires PHP
5.2+
Tested up to
WP 7.1
Created
2008-06-16 (19y ago)

Login Lockdown records the IP address and timestamp of failed login attempts. If more than a selected number of attempts are detected within a set period of time from the same IP, then the login is disabled for all requests from that IP address (or the IP is completely blocked from accessing the site). This secures the site and helps prevent brute force password attacks & discovery. The plugin defaults to a 1 hour lock out of an IP block after 3 failed login attempts within 5 minutes. This can be modified in options. Administrators can release locked out IPs manually from the panel. A detailed log is available for all failed login attempts and all IP locks to control lockdown. Configure the plugin from Settings – Login Lockdown. Country blocking (PRO feature) Block unwanted countries from accessing the site, or block them from being able to log in. Display a custom message to blocked visitors so they know why they can’t access the site. Captcha The simplest way to get rid of bots and brute-force password attacks. Choose from 5 different versions – built-in one, two from Google (PRO feature), Cloudflare Turnstile, and hCaptcha (PRO feature). Built-in captcha is GDPR compatible. 2FA – Two Factor Authentication (PRO feature) Provide an extra layer of security without 2FA code generating apps such as Google Authenticator. Even if somebody knows your username & password they won’t be able to log in because it needs to be confirmed by clicking a unique link sent to your email. Since you’re the only one that has access to your inbox, you’ll never get hacked. Cloud Protection (PRO feature) Manage IP Whitelists and Blacklists in your Login Lockdown Dashboard (a SaaS service for managing all your sites) and apply them to protect all the sites you manage from a single location. Temporary Access (PRO feature) Give temporary access to other people without giving them a username & password. Set the lifetime of the link and the maximum number of times it can be used to prevent abuse. Access level rights can be any you pick – admin, editor, author…

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C