Impact
The vulnerability exists in the Limit Login Attempts Reloaded WordPress plugin before version 3.3.5. The plugin fails to perform a case‑insensitive comparison against the username denylist and does not consider the account’s email address. As a result, an administrator or blocking user intended to be prevented from logging in can authenticate with a case‑variant username or by using the associated email address. This flaw allows an attacker to bypass the denylist, leading to unauthorized access to the site’s administrative functions. The weakness is consistent with improper authentication checks.
Affected Systems
Any WordPress installation that uses the Limit Login Attempts Reloaded plugin with a version earlier than 3.3.5 and includes a denylisted username or email address. The issue applies to the plugin itself; no other products are affected.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and the EPSS score is not available, suggesting no known widespread exploitation. The vulnerability is listed as not present in the CISA KEV catalog. Attackers would need to target the WordPress web interface, exploit the denial list bypass through the login form, and rely on knowledge of or guesswork around the case-sensitive username or email. While the impact is limited to unauthorized authentication, it grants full administrative access if the blocked account is privileged. The lack of a publicly documented exploit reduces immediate risk, but any attacker who can discover or guess a denylisted credential can exploit the flaw.
OpenCVE Enrichment