WP Limit Login Attempts

WP Limit Login Attempts has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2022; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 8.2, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is SQL Injection, behind 1 of the records (50%). Other recurring categories include Use Of Less Trusted Source.

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2022.

2 independent researchers contributed these findings, one record each. WP Limit Login Attempts is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
8.2/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all WP Limit Login Attempts vulnerabilities before they are exploited.

Most severe open issueCVSS 6.5CVE-2022-4303

WP Limit Login Attempts <= 2.6.4 - IP Spoofing to Protection Mechanism Bypass

Read the full analysis

Vulnerability Records

2 records
WP Limit Login Attempts banner
Latestv2.6.5

WP Limit Login Attempts

Arshid

Author

Arshid

4.6(300)
92/100
Last Updated
2026-05-20 (4mo ago)
Active Installs
10,000+
Downloads
445,735
Requires WP
6.0+
Requires PHP
5.6+
Tested up to
WP 7.0.4
Created
2015-08-19 (11y ago)

Limit Login Attempts for login protection, protect site from brute force attacks.Brute Force Attack aims at being the simplest kind of method to gain access to a site: it tries usernames and passwords, over and over again, until it gets in. WP Limit Login Attempts plugin limit rate of login attempts and block IP temporarily. It is detecting bots by captcha verification. Go to Settings > WP Limit Login. Features Login Security – Limit Login Attempts and track user login attempts Captcha Verification Light weight plugin Mechanism for slow down brute force attack Redirect to home page, when abnormal request (It will stop hacking tools) GDPR compliant. With this feature turned on, all logged IPs get obfuscated (md5-hashed). Limit Login Attempts A brute force attack is a trial-and-error mеthоd uѕеd tо оbtаin infоrmаtiоn such аѕ a user раѕѕwоrd оr реrѕоnаl idеntifiсаtiоn number (PIN). In a brute force attack, аutоmаtеd software iѕ uѕеd tо gеnеrаtе a lаrgе numbеr оf соnѕесutivе guesses аѕ to thе value of thе desired data. Brute force attack may bе uѕеd by сriminаlѕ tо crack еnсrурtеd dаtа, оr bу security аnаlуѕtѕ to tеѕt an оrgаnizаtiоn’ѕ nеtwоrk security. If уоu аdорt thе use оf this plugin, it will limit thе number оf timеѕ a uѕеr can аttеmрt tо log intо уоur ассоunt. Aftеr a сарtсhа verification would have bееn rеԛuеѕtеd, thе mесhаniѕm will ѕlоw dоwn brutе fоrсе аttасk hаving thе роwеr tо redirect tо home page аnd соmрlеtеlу аvоid intruder intо уоur рrесiоuѕ ассоunt. Captcha Verification WP Limit Login Attempts plugin provides an extra protection by Captcha. Captcha Verification in seven attempts. It will be highly helpful for removing bots. For more service ,Please visit Donations WP Limit Login Attempts plugin protecting your admin. Please make donation, I really appreciate it . Support http://www.ciphercoin.com/contact/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C