Limit Login Attempts Project maintains a WordPress plugin focused on brute-force protection through login-attempt throttling, with its vulnerability profile centered on the plugin's direct handling of user input and authentication logic. The recurring exposure reflects characteristic web-application weaknesses including cross-site scripting, SQL injection, and improper authentication mechanisms that arise in access-control and form-processing components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Limit Login Attempts Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0787CRITICAL The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available | Mar 28, 2022 | 9.8 | 45 | NO | YES |
CVE-2023-1861MEDIUM The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated | May 2, 2023 | 5.4 | 32 | NO | NO |
CVE-2021-24657MEDIUM The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logi | Sep 20, 2021 | 6.1 | 30 | NO | YES |
CVE-2012-10001CRITICAL The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authen | Jan 6, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-1912MEDIUM The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient | Apr 6, 2023 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Limit Login Attempts Project.
Media articles that mention a CVE ID that affects a product developed by Limit Login Attempts Project — matched by CVE ID, not by vendor name.