Impact
Based on the description, the Limit Login Attempts Reloaded WordPress plugin fails to perform a case‐insensitive comparison against its username denylist and does not consider the account’s email address. As a result, an account that an administrator intended to block can still authenticate using a case‑variant username or its associated email address. This flaw allows an attacker to bypass the denylist, potentially gaining unauthorized access to administrative functions.
Affected Systems
Any WordPress installation that uses the Limit Login Attempts Reloaded plugin with a version earlier than 3.3.5 and includes a denylisted username or email address. The issue applies to the plugin itself; no other products are affected.
Risk and Exploitability
Based on the description, the likely attack vector involves an attacker interacting with the WordPress login interface, attempting to authenticate with a case‑variant username or the associated email address of a block‑listed account. The vulnerability carries a CVSS score of 3.7, indicating low severity. No EPSS data is available, implying limited evidence of widespread exploitation. The issue is not listed in the CISA KEV catalog. If exploited, the flaw would grant administrative access when the blocked account has privileged rights. The absence of a confirmed public exploit reduces immediate risk but does not eliminate the possibility for an attacker with knowledge or guesswork around the blocked credential.
OpenCVE Enrichment