CVE Database /
CVE-2020-35590
CVE · Critical
CVE-2020-35590 — Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-35590
|
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention [limit-login-attempts-reloaded] < 2.17.4 |
Improper Restriction of Excessive Authentication Attempts |
Critical
9.8
|
< 2.17.4
|
2.17.4 |
2020-12-14 |
—
|
CVE-2020-35590
The limit-login-attempts-reloaded plugin before version 2.17.4 contains a rate limiting bypass vulnerability in how it processes client IP addresses. When the plugin is configured to trust the X-Forwarded-For header for determining client IP addresses, attackers can forge this header with arbitrary values to circumvent per-IP brute force protections. By supplying different header values with each login attempt, an attacker can prevent the login counter from reaching the configured maximum retry threshold, allowing unlimited brute force attacks against user accounts.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings