Limit Login Attempts Reloaded is a WordPress plugin that controls authentication flow through login-attempt throttling, where its disclosures center on cross-site scripting, excessive-authentication-attempt handling, and authorization gaps inherent to access-control logic in authentication middleware. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Limitloginattempts over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35590CRITICAL LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header ca | Dec 21, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-35589MEDIUM The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administr | Dec 21, 2020 | 5.4 | 19 | NO | NO |
CVE-2023-5525MEDIUM The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle t | Nov 27, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-6934MEDIUM The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due | Jan 11, 2024 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Limitloginattempts.
Media articles that mention a CVE ID that affects a product developed by Limitloginattempts — matched by CVE ID, not by vendor name.