Known vulnerabilities in Limit Login Attempts
Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.
6Reported vulnerabilities
9.8Highest CVSS score
1.7.2Latest version
300,000+Active installs
What to do now
Update Limit Login Attempts to 1.7.2 or later.
6 of these have a fixed version available. Updating resolves them.
This plugin has not been updated in over two years. New vulnerabilities may never be fixed. Consider an alternative.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2023-1861 | Medium | 28.8% | 1.7.2 and earlier | 1.7.2 |
May 2, 2023 |
| CVE-2022-0787 | Critical | 8.6% | Before 5.1 | 5.1 |
March 28, 2022 |
| CVE-2021-24657 | Medium | 1.6% | Before 4.0.50 | 4.0.50 |
September 20, 2021 |
| CVE-2012-10001 | Critical | 2.5% | Before 1.7.1 | 1.7.1 |
January 6, 2021 |
| CVE-2022-1029 | Medium | 0.9% | Before 4.0.72 | 4.0.72 |
June 27, 2022 |
| CVE-2023-1912 | Medium | 0.8% | 1.7.1 and earlier | 1.7.2 |
April 6, 2023 |