CVE · Critical

CVE-2020-35590 — Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-35590 Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4 Improper Restriction of Excessive Authentication Attempts Critical 9.8 < 2.17.4 2.17.4 2020-12-14

CVE-2020-35590

The limit-login-attempts-reloaded plugin before version 2.17.4 contains a rate limiting bypass vulnerability in how it processes client IP addresses. When the plugin is configured to trust the X-Forwarded-For header for determining client IP addresses, attackers can forge this header with arbitrary values to circumvent per-IP brute force protections. By supplying different header values with each login attempt, an attacker can prevent the login counter from reaching the configured maximum retry threshold, allowing unlimited brute force attacks against user accounts.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.