Description
The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.
Published: 2026-08-21
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass via denylist
Action: Apply Patch
AI Analysis

Impact

Based on the description, the Limit Login Attempts Reloaded WordPress plugin fails to perform a case‐insensitive comparison against its username denylist and does not consider the account’s email address. As a result, an account that an administrator intended to block can still authenticate using a case‑variant username or its associated email address. This flaw allows an attacker to bypass the denylist, potentially gaining unauthorized access to administrative functions.

Affected Systems

Any WordPress installation that uses the Limit Login Attempts Reloaded plugin with a version earlier than 3.3.5 and includes a denylisted username or email address. The issue applies to the plugin itself; no other products are affected.

Risk and Exploitability

Based on the description, the likely attack vector involves an attacker interacting with the WordPress login interface, attempting to authenticate with a case‑variant username or the associated email address of a block‑listed account. The vulnerability carries a CVSS score of 3.7, indicating low severity. No EPSS data is available, implying limited evidence of widespread exploitation. The issue is not listed in the CISA KEV catalog. If exploited, the flaw would grant administrative access when the blocked account has privileged rights. The absence of a confirmed public exploit reduces immediate risk but does not eliminate the possibility for an attacker with knowledge or guesswork around the blocked credential.

Generated by OpenCVE AI on August 21, 2026 at 17:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Limit Login Attempts Reloaded plugin to version 3.3.5 or later.
  • If an immediate upgrade is not possible, manually enforce a case‑insensitive denylist by adding blocked usernames or emails to a separate restriction that the plugin does not ignore, or disable the plugin’s denylist feature altogether.
  • Regularly audit user account permissions and enforce strong, unique passwords for all administrative accounts.

Generated by OpenCVE AI on August 21, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Limit Login Attempts Project
Limit Login Attempts Project limit Login Attempts
Wordpress
Wordpress wordpress
Vendors & Products Limit Login Attempts Project
Limit Login Attempts Project limit Login Attempts
Wordpress
Wordpress wordpress

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 21 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-184
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.
Title Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Variant and Account Email
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Limit Login Attempts Project Limit Login Attempts
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-21T12:46:58.438Z

Reserved: 2026-07-30T08:11:55.659Z

Link: CVE-2026-18356

cve-icon Vulnrichment

Updated: 2026-08-21T12:46:47.218Z

cve-icon NVD

Status : Deferred

Published: 2026-08-21T12:16:24.863

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-18356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:30:07Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs