Limit Login Attempts (Spam Protection)
Limit Login Attempts (Spam Protection) has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2024; all 5 are fixed as of September 2026. Their average CVSS score is 8.0, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is SQL Injection, behind 2 of the records (40%). Other recurring categories include Cross-Site Request Forgery (CSRF), Improper Authorization.
Every one of the 5 issues recorded for Limit Login Attempts (Spam Protection) has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, most of them (2) reported by Bugbang. Limit Login Attempts (Spam Protection) is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2022-0787Limit Login Attempts (Spam Protection) <= 4.9.1 - Unauthenticated SQL Injection
Read the full analysisVulnerability Records

Limit Login Attempts (Spam Protection)
Author
wp-buy
Limit the number of login attempts possible both through normal login as well as using auth cookies. By default WordPress allows unlimited login attempts either through the login page or by sending special cookies. This allows passwords (or hashes) to be brute-force cracked with relative ease. Limit Login Attempts blocks an Internet address from making further attempts after a specified limit on retries is reached, making a brute-force attack difficult or impossible. Basic Features Limit the number of retry attempts when logging in. Configurable lockout timings. Email notification of blocked attempts (Detailed email containing all necessary information). Notify the user of remaining attempts. Report containing all blocked attempts. Whitelist/Blocklist of IPs (Support IP ranges). Allow/Block Countries. Automatically block IP addresses that exceed limit login attempts Automatically add IP addresses that exceed blocks limit to the deny list Send notifications about blocked retry (Email sent to admins) Inform the user about the remaining retries or lockout time on the login page. Unlock The Locked users – Easily unlock the locked admin through the email or dashboard. Limit the number of retry attempts when logging in per IP. Limit the number of attempts to log in using cookies. Optional logging and optional email notification. Compatible with Google captcha, Captcha Plus & reCaptcha. Dashboard gives you an overview of your site’s security. Enable or disable the plugin functionality Enable to disable email notifications Compatible with latest WordPress version Woocommerce login page protection. Wordfence & Sucuri compatibility. GDPR compliant. Advanced Features (PRO) All Basic features included. Save the password that was used by the hacker (Save part of the password and hide the last three digits). Advanced dashboard gives you an overview of your site’s security (Charts for the most important reports). Block attackers by IP, Country, IP range. Mobile Application for the admins to follow up the site security (Download APK). Video Description Plugin Settings and Reports
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C