Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Limit Login Attempts Project

First CVE: Jan 6, 2021Active for: 6 yearsTotal CVEs: 5

Limit Login Attempts Project maintains a WordPress plugin focused on brute-force protection through login-attempt throttling, with its vulnerability profile centered on the plugin's direct handling of user input and authentication logic. The recurring exposure reflects characteristic web-application weaknesses including cross-site scripting, SQL injection, and improper authentication mechanisms that arise in access-control and form-processing components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 78% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Limit Login Attempts Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 6, 2021
5 years ago
Most Recent CVE
May 2, 2023
1,183 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-0787CRITICAL
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available
Mar 28, 20229.845NOYES
CVE-2023-1861MEDIUM
The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated
May 2, 20235.432NONO
CVE-2021-24657MEDIUM
The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logi
Sep 20, 20216.130NOYES
CVE-2012-10001CRITICAL
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authen
Jan 6, 20219.830NONO
CVE-2023-1912MEDIUM
The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient
Apr 6, 20236.122NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
60%
40%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None4 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
40.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Limit Login Attempts Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Limit Login Attempts Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Limit Login Attempts Project's Products

View all 3 CNAs →

Top CWEs