Login Lockdown & Protection <= 2.14 - IP Block Bypass
2025-12-12 15:27
William CookeStrategic Overview
StatusPatched in 2.15
Affected PluginLogin Lockdown & Protection
Affected Version
<= 2.14CVSS5.3Medium
CVE
CVE-2025-11707Vulnerability Overview
The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an administrative user email, to generate valid unblock keys for their IP Address. This makes it possible for unauthenticated attackers to bypass blocks due to invalid login attempts.
Technical Analysis
REMEDIATION: Update to version 2.15, or a newer patched version --- IDENTIFIER: CWE-330 (Use of Insufficiently Random Values) The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C