CVE · Critical

CVE-2012-10001 — Limit Login Attempts [limit-login-attempts] < 1.7.1 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2012-10001 Limit Login Attempts [limit-login-attempts] < 1.7.1 (closed) Improper Authentication Critical 9.8 < 1.7.1 1.7.1 2012-06-01

CVE-2012-10001

The Limit Login Attempts plugin before version 1.7.1 had a flaw where authentication cookies were not properly cleared during account lockouts due to a regression introduced in version 1.6.2. This vulnerability allowed attackers to continue attempting to crack the authentication cookies even while the account was locked, bypassing the lockout protection that should have prevented such attacks. While authentication cookies are cryptographically resistant to brute force attempts, the failure to enforce lockouts removed an important security layer that should have been in place.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.