WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms

Protect your WordPress website from brute force attacks by limiting the number of failed login attempts. Improve security and stop bots.

3Reported vulnerabilities
9.8Highest CVSS score
1.3.2Latest version
4,000+Active installs

What to do now

Update Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms to 1.3.0 or later. 3 of these have a fixed version available. Updating resolves them.

Plugin last updated: January 9, 2026 / Tested up to WordPress: 6.8.8 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2015-9335 Critical 9.8 1.8% Before 1.1.1 1.1.1 August 22, 2019
CVE-2024-30439 Medium 6.1 0.4% 1.2.9 and earlier 1.3.0 March 28, 2024
WF-3eb4b3e7-6aad-4201-b48b-c8d788eb8acf Medium 6.1 Before 1.1.8 1.1.8 April 12, 2017

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.