plugin

Login Lockdown Vulnerabilities

11 known security issues reported for the Login Lockdown WordPress plugin. Most recent disclosed Dec 13, 2025.

1 high 4 medium

Running Login Lockdown on your site? Check whether your installed version is affected.

Scan your site free

Login Lockdown &amp; Protection [login-lockdown] < 2.15

unknown

[en] The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an administrative user email, to generate valid unblock keys for their IP Addr...

Affected:
up to 2.15
Fixed in:
2.15
Disclosed:
Dec 13, 2025

CVE-2025-11707 on NVD →

Login Lockdown & Protection <= 2.14 - IP Block Bypass

medium

The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an administrative user email, to generate valid unblock keys for their IP Address....

CVSS:
5.3
Affected:
up to 2.14
Fixed in:
2.15
Disclosed:
Dec 12, 2025

CVE-2025-11707 on NVD →

Login Lockdown & Protection <= 2.11 - Missing Authorization to Authenticated (Subscriber+) Arbitrary IP Whitelisting

medium

The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in all versions up to, and including, 2.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain a valid nonce...

CVSS:
5.4
Affected:
up to 2.11
Fixed in:
2.12
Disclosed:
May 6, 2025

CVE-2025-3766 on NVD →

Login Lockdown &amp; Protection [login-lockdown] < 2.09

unknown

[en] The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_export_file function in all versions up to, and including, 2.08. This makes it possible for authenticated attackers, with subscriber access and higher, to expo...

Affected:
up to 2.09
Fixed in:
2.09
Disclosed:
Feb 20, 2024

CVE-2024-1340 on NVD →

Login Lockdown – Protect Login Form <= 2.08 - Missing Authorization

medium

The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_export_file function in all versions up to, and including, 2.08. This makes it possible for authenticated attackers, with subscriber access and higher, to export th...

CVSS:
5.4
Affected:
up to 2.08
Fixed in:
2.09
Disclosed:
Feb 9, 2024

CVE-2024-1340 on NVD →

Login Lockdown &amp; Protection [login-lockdown] < 2.07

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login Form.This issue affects Login Lockdown – Protect Login Form: from n/a through 2.06.

Affected:
up to 2.07
Fixed in:
2.07
Disclosed:
Dec 29, 2023

CVE-2023-50837 on NVD →

Login Lockdown – Protect Login Form <= 2.06 - Authenticated(Administrator+) SQL Injection

medium

The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to SQL Injection via the 'iDisplayStart' parameter in all versions up to 2.07 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authe...

CVSS:
6.6
Affected:
up to 2.07
Fixed in:
2.07
Disclosed:
Dec 21, 2023

CVE-2023-50837 on NVD →

Login Lockdown <= 2.06 - Authenticated (Administrator+) SQL Injection

high

The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to SQL Injection via the ‘sort order and limit’ parameter in all versions up to 2.06 (inclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...

CVSS:
7.2
Affected:
up to 2.06
Fixed in:
2.07
Disclosed:
Nov 21, 2023

Login Lockdown &amp; Protection [login-lockdown] < 2.07

unknown

The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to SQL Injection via the ‘sort order and limit’ parameter in all versions up to 2.06 (inclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...

Affected:
up to 2.07
Fixed in:
2.07
Disclosed:
Nov 21, 2023

Login Lockdown &amp; Protection [login-lockdown] < 2.07

unknown

The plugin is vulnerable to SQL Injection via the &lsquo;sort order and limit&rsquo; parameter due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

Affected:
up to 2.07
Fixed in:
2.07

Login Lockdown &amp; Protection [login-lockdown] < 2.12

unknown
Affected:
up to 2.12
Fixed in:
2.12

CVE-2025-3766 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database