Description
WordPress Plugin WP Limit Login Attempts is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass the IP-based restrictions on login forms. WordPress Plugin WP Limit Login Attempts version 2.6.4 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Gravity Forms Information Disclosure (2.4.8)
SharePoint CVE-2025-29976 Vulnerability (CVE-2025-29976)
MongoDb Other Vulnerability (CVE-2019-20923)
WordPress Plugin LISL Last-Image Slider TimThumb Arbitrary File Upload (1.0)
WordPress Plugin Product list Widget for Woocommerce Cross-Site Scripting (1.0)