Login Lockdown & Protection <= 2.14 - IP Block Bypass

2025-12-12 15:27
William Cooke

Strategic Overview

Status
Patched in 2.15
Affected Version<= 2.14
CVSS5.3Medium
CVECVE-2025-11707
View all Login Lockdown & Protection vulnerabilities

Vulnerability Overview

The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an administrative user email, to generate valid unblock keys for their IP Address. This makes it possible for unauthenticated attackers to bypass blocks due to invalid login attempts.

Technical Analysis

REMEDIATION: Update to version 2.15, or a newer patched version --- IDENTIFIER: CWE-330 (Use of Insufficiently Random Values) The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C