Login Lockdown & Protection [login-lockdown] < 2.15
unknown
[en] The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an administrative user email, to generate valid unblock keys for their IP Addr...
- Affected:
- up to 2.15
- Fixed in:
- 2.15
- Disclosed:
- Dec 13, 2025
CVE-2025-11707 on NVD →
Login Lockdown & Protection <= 2.14 - IP Block Bypass
medium
The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an administrative user email, to generate valid unblock keys for their IP Address....
- CVSS:
- 5.3
- Affected:
- up to 2.14
- Fixed in:
- 2.15
- Disclosed:
- Dec 12, 2025
CVE-2025-11707 on NVD →
Login Lockdown & Protection <= 2.11 - Missing Authorization to Authenticated (Subscriber+) Arbitrary IP Whitelisting
medium
The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in all versions up to, and including, 2.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain a valid nonce...
- CVSS:
- 5.4
- Affected:
- up to 2.11
- Fixed in:
- 2.12
- Disclosed:
- May 6, 2025
CVE-2025-3766 on NVD →
Login Lockdown & Protection [login-lockdown] < 2.09
unknown
[en] The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_export_file function in all versions up to, and including, 2.08. This makes it possible for authenticated attackers, with subscriber access and higher, to expo...
- Affected:
- up to 2.09
- Fixed in:
- 2.09
- Disclosed:
- Feb 20, 2024
CVE-2024-1340 on NVD →
Login Lockdown – Protect Login Form <= 2.08 - Missing Authorization
medium
The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_export_file function in all versions up to, and including, 2.08. This makes it possible for authenticated attackers, with subscriber access and higher, to export th...
- CVSS:
- 5.4
- Affected:
- up to 2.08
- Fixed in:
- 2.09
- Disclosed:
- Feb 9, 2024
CVE-2024-1340 on NVD →
Login Lockdown & Protection [login-lockdown] < 2.07
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login Form.This issue affects Login Lockdown – Protect Login Form: from n/a through 2.06.
- Affected:
- up to 2.07
- Fixed in:
- 2.07
- Disclosed:
- Dec 29, 2023
CVE-2023-50837 on NVD →
Login Lockdown – Protect Login Form <= 2.06 - Authenticated(Administrator+) SQL Injection
medium
The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to SQL Injection via the 'iDisplayStart' parameter in all versions up to 2.07 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authe...
- CVSS:
- 6.6
- Affected:
- up to 2.07
- Fixed in:
- 2.07
- Disclosed:
- Dec 21, 2023
CVE-2023-50837 on NVD →
Login Lockdown <= 2.06 - Authenticated (Administrator+) SQL Injection
high
The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to SQL Injection via the ‘sort order and limit’ parameter in all versions up to 2.06 (inclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...
- CVSS:
- 7.2
- Affected:
- up to 2.06
- Fixed in:
- 2.07
- Disclosed:
- Nov 21, 2023
Login Lockdown & Protection [login-lockdown] < 2.07
unknown
The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to SQL Injection via the ‘sort order and limit’ parameter in all versions up to 2.06 (inclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...
- Affected:
- up to 2.07
- Fixed in:
- 2.07
- Disclosed:
- Nov 21, 2023
Login Lockdown & Protection [login-lockdown] < 2.07
unknown
The plugin is vulnerable to SQL Injection via the ‘sort order and limit’ parameter due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
- Affected:
- up to 2.07
- Fixed in:
- 2.07
Login Lockdown & Protection [login-lockdown] < 2.12
unknown
- Affected:
- up to 2.12
- Fixed in:
- 2.12
CVE-2025-3766 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database