CVE-2012-10001
The Limit Login Attempts plugin before version 1.7.1 had a flaw where authentication cookies were not properly cleared during account lockouts due to a regression introduced in version 1.6.2. This vulnerability allowed attackers to continue attempting to crack the authentication cookies even while the account was locked, bypassing the lockout protection that should have prevented such attacks. While authentication cookies are cryptographically resistant to brute force attempts, the failure to enforce lockouts removed an important security layer that should have been in place.
Based on public CVE data (MITRE/NVD).